Starting July 14, 2026, Chrome's Gemini-powered AI features rolled out to desktop users in the United Kingdom, with an iOS expansion planned for the following month. On the surface, that's a straightforward consumer feature rollout: UK users can now chat with a browsing assistant that summarizes long pages, compares information across open tabs, and integrates with Gmail, Calendar, and Maps. But the more consequential story sits one layer up, in the enterprise product Google has been quietly building around the same underlying technology. Chrome Enterprise Premium, priced at $6 per user per month, is turning the browser itself into an autonomous work agent — one that can complete multi-step tasks across websites without a human clicking through each step, and one that's already reporting a measurable reduction in a specific enterprise security risk that's been growing all year: unauthorized data flowing into AI tools.
What actually shipped for consumers
The UK rollout brings Chrome's existing Gemini side-panel functionality to a new market, letting users summarize lengthy articles or research papers, ask questions grounded in the content of the page they're viewing, and compare details across multiple open tabs without manually cross-referencing them. The assistant integrates directly with core Google apps — Gmail, Calendar, Maps — letting it pull context from a user's existing Google account data to make its answers and suggestions more specific. None of this is architecturally new; it's the geographic expansion of a feature set Google has been rolling out market by market, with the UK joining a growing list of regions where Gemini in Chrome is generally available on desktop.
The more interesting product: Chrome Enterprise Premium
The consumer rollout is worth noting mainly because it shares underlying technology with a considerably more ambitious enterprise product. Chrome Enterprise Premium, available at $6 per user per month, repositions Chrome as what Google is explicitly calling an agentic workplace platform rather than just a browser with an AI assistant bolted on. Three features define that repositioning.
Auto Browse, powered by Gemini 3, is the most significant: it lets Chrome handle multi-step tasks autonomously across websites, without a user manually navigating each step. Google's own examples include scheduling appointments, filling out forms, collecting documents from across multiple sources, filing expense reports, and managing recurring subscriptions — tasks that today typically require a human to click through several different pages, copy information between them, and confirm each step manually. Auto Browse is designed to take that multi-step workflow and execute it end to end, with the browser itself acting as the agent rather than requiring a separate automation tool bolted onto the browsing experience.
Chrome Skills addresses a different, more habitual pain point: the tendency for knowledge workers to ask an AI assistant the same type of question or request the same type of task repeatedly throughout a workday. Skills let a user save a prompt as a reusable workflow, then trigger it instantly on any page by typing "/" in the Gemini side panel and selecting the saved Skill — turning a one-off prompt into a repeatable, shareable piece of team tooling that builds up over time into a library of workflows customized to how a specific person or team actually works.
The third piece, real-time data loss prevention, is arguably the most consequential for enterprise security teams specifically. Chrome Enterprise Premium's DLP capability restricts copy, paste, upload, download, and print actions based on the sensitivity of the content involved, with data masking and dynamic watermarking layered on top. Google reports that organizations using these DLP restrictions have seen a 50% reduction in content transfers to unauthorized AI tools — a concrete, measurable outcome addressing a problem that's become one of the most common and hardest-to-govern shadow IT risks of the past two years: employees pasting sensitive company data into consumer AI chat tools that sit entirely outside IT's visibility or control.
Why the agentic framing is the real shift, not the AI assistant framing
It's worth separating two different things Google is doing here, because they represent genuinely different levels of ambition. An AI assistant that summarizes pages and answers questions is a productivity feature — useful, but conceptually similar to features every major software vendor has shipped over the past two years. Auto Browse is a different category of product: it's the browser taking autonomous action on a user's behalf across multiple websites and sessions, without requiring step-by-step human confirmation at each stage. That's the same broad shift toward agentic AI that's shown up across enterprise software this year — coding agents that execute multi-step tasks without turn-by-turn chat, customer service agents that resolve tickets end to end, and now, a browser that completes workflows across the open web the way a human assistant would, but without a human actually doing the clicking.
Google has also signaled where this is headed next: plans to integrate Auto Browse with "Gemini Spark" in the coming months would give users a persistent, 24/7 personal AI agent capable of taking actions in the browser on their behalf continuously, rather than only when explicitly invoked for a specific task. That's a meaningfully more ambitious vision than the current Auto Browse feature set, and it's worth enterprise IT and security teams tracking closely, since a persistent, always-on agent with browsing and action-taking capability raises a different and larger set of governance questions than a request-and-response assistant does.
The governance stakes for enterprise IT
For enterprise IT and security teams, Chrome Enterprise Premium's DLP-driven reduction in unauthorized AI data transfers is the headline number worth internalizing, because it quantifies a problem most organizations have struggled to even measure, let alone control. The instinct among employees to paste a chunk of a contract, a customer list, or an internal document into whatever AI chat tool is fastest and most familiar has been one of the defining shadow-IT risks of the current AI wave, precisely because it's nearly invisible to conventional network and endpoint monitoring — it looks like normal web traffic to a legitimate site, not like a data exfiltration event. A 50% reduction, if it holds up across a broader customer base than Google's own reported figures, represents a genuinely significant improvement in a risk category that's been difficult to address with policy alone.
At the same time, Auto Browse and agentic browsing more broadly introduce a new governance surface that didn't exist in the request-and-response assistant model: an agent taking autonomous, multi-step action across external websites on an employee's behalf needs its own access controls, audit logging, and guardrails against taking an action a human wouldn't have approved if asked directly. IT teams evaluating Chrome Enterprise Premium should specifically scope out how Auto Browse's audit trail works, what approval gates exist before the agent takes an action with real-world consequences (submitting a form, making a purchase, sending a message), and how that activity gets logged and reviewed — questions that are considerably more involved than the vendor evaluation checklist most teams have built for a simple AI chat assistant.
How this compares to other agentic browser plays
Google isn't the only company betting the browser itself becomes the primary agentic AI surface — Perplexity's Comet browser and other agentic browser entrants have been making similar bets throughout 2026, and the competitive dynamic between them is worth watching specifically because each is making a slightly different architectural choice about where the agent's intelligence actually lives. Some competing approaches route agentic browsing tasks through a third-party model regardless of which browser chrome the user sees, essentially treating the browser as a thin client for an external agent. Google's approach, by integrating Auto Browse and Gemini 3 directly into Chrome at the platform level with enterprise-grade DLP and governance controls layered in from the start, is a distinctly platform-vendor move — leveraging Chrome's existing enterprise deployment footprint and device management relationships rather than asking IT teams to onboard an entirely new browser just to get agentic capability. For enterprise IT teams already standardized on Chrome for device management, that distinction meaningfully lowers the adoption friction compared to evaluating and rolling out a separate agentic browser product from scratch.
Practical takeaways
If your organization is already dealing with employees pasting sensitive data into unsanctioned AI tools, evaluate Chrome Enterprise Premium's DLP capability specifically against that risk — the 50% reduction Google reports is a meaningful data point, even accounting for it being a vendor-reported figure. Before rolling out Auto Browse to any team, scope out the audit logging and approval-gate model for autonomous actions with real-world consequences, since agentic browsing introduces a governance surface that a simple AI chat assistant doesn't. Track Google's planned integration of Auto Browse with Gemini Spark for a persistent, always-on browser agent, since that's a meaningfully larger governance lift than the current on-demand Auto Browse feature. And treat Chrome Skills as a genuinely useful, lower-risk entry point for enterprise AI adoption — reusable, team-shared workflows built on top of an existing assistant carry far less governance complexity than autonomous multi-step task execution, and are a reasonable place to start building organizational AI literacy before tackling Auto Browse more broadly.
The UK expansion of Gemini in Chrome is a minor, expected geographic rollout. The more important story is that Google has quietly built, and started shipping in production, a version of the browser that doesn't just answer questions about the page you're looking at — it takes multi-step action across the web on your behalf, for $6 a month, with enterprise governance controls attached. That's a different product category than "AI assistant in the browser," and it's worth IT leaders evaluating it as such.