Perplexity has made Anthropic's Claude Opus 4.6 the default model powering Comet's browser agent for Max subscribers, with Claude Sonnet 4.5 available as an alternative. The change, rolled out in July 2026, means the flagship feature of Perplexity's own AI browser now runs, by default, on a frontier model built entirely by a different company. Perplexity says Opus 4.6 meaningfully improves Comet's reasoning on multi-step tasks — parsing data patterns on a live web dashboard, tracing a GitHub repository's commit history for behavioral trends, or walking through a competitor's onboarding flow to flag friction points — the kind of work that requires the agent to hold context across many pages and actions, not just answer one question well. The same release cycle brought "Personal Computer" to all Mac users, extending Perplexity's desktop app beyond the browser into local file editing, native app control, and voice-driven orchestration of the whole machine. Together, the two moves say something clearer than either headline alone: Perplexity is betting its product is the agent's judgment and orchestration layer, not the model doing the reasoning underneath it — and it's willing to hand that reasoning to a competitor's LLM to prove it.
What actually shipped
Comet has been building toward this moment since it first launched for Windows and macOS on July 9, 2025. An Android version followed on November 20, 2025, an iOS app arrived March 18, 2026, and Perplexity made the browser free for all users by October 2025 after initially gating it behind paid tiers — a sequence that reads like a company racing for distribution before monetizing the harder, more valuable layer. That harder layer turned out to be the agent itself: a sidebar assistant that keeps context across an entire browsing session, can compare products across multiple open tabs, fill out forms, complete simple purchases, manage email, and now, for Max subscribers, choose which frontier model actually does the thinking. Perplexity reportedly raised $200 million earlier in 2026 specifically tied to Comet's development, a figure that underlines how central the browser has become to the company's strategy beyond its original search-answer product.
Personal Computer, meanwhile, moved out of limited testing to general availability on Mac in May 2026 and picked up expanded capabilities through the spring — reading, writing, and searching local files across any connected folder, operating native apps like Mail and Finder directly, and accepting spoken commands that it can act on without the user touching a keyboard. Combined with Comet's browser-native agent, Perplexity is assembling something closer to a full desktop operating layer than a search engine with a chat window bolted on. The company's own positioning increasingly treats the browser and the desktop app as the product, with the underlying model as a swappable component.
Why defaulting to someone else's model is the real story
It would have been easy for Perplexity to keep pushing its own in-house models as Comet's default, the way most AI product companies reflexively favor their own stack for a flagship feature. Instead, Max subscribers get Opus 4.6 by default and can switch to Sonnet 4.5, and Perplexity is marketing that choice as a feature rather than hiding it. That's a meaningful admission: Perplexity is telling its most valuable customers that the best available reasoning engine, for now, belongs to Anthropic, and that its own competitive advantage lies elsewhere — in the browser chrome, the action-taking plumbing, the memory across a session, the integrations with email and calendars and local files.
This mirrors a broader pattern that's been building across the industry throughout 2026: model-agnostic, bring-your-own-model architectures are becoming the norm rather than the exception for products built on top of frontier LLMs. Enterprise AI platforms increasingly let customers pick between Claude, GPT, and Gemini variants depending on task and cost profile rather than locking into a single vendor. The logic is the same one playing out in Comet — the model layer is commoditizing faster than the application layer, and the companies racing to own users are betting that orchestration, context management, and the last-mile plumbing of "actually doing the task in a real browser on a real webpage" is where the durable value sits, not in training the underlying transformer. Perplexity's own history reinforces this: it has never trained a leading frontier model itself and has built its entire business on wrapping other people's models with better retrieval, better UX, and now better agentic execution. Defaulting Comet to Opus 4.6 is Perplexity leaning into that identity rather than fighting it.
It's also a bet that pays off differently depending on who wins the underlying model race next. If Anthropic's models stay ahead on the kind of long-horizon, tool-using reasoning that agentic browsing requires, Perplexity benefits without having spent the billions needed to train that capability itself. If a competitor pulls ahead, Perplexity's architecture is already built to swap the engine without rebuilding the car. That flexibility is a real strategic asset — but it also means Perplexity's core differentiation is now explicitly downstream of decisions made in Anthropic's and OpenAI's training rooms, not its own.
The security problem nobody has actually solved
The harder question is whether an agent this capable should be running unsupervised in a browser at all, regardless of which model sits behind it. Comet's core abilities — reading a page, filling in forms, clicking through checkout flows, reaching into connected email — are exactly the capabilities that make prompt injection dangerous rather than theoretical. Researchers at Brave demonstrated an attack chain against Comet where a malicious webpage's hidden instructions caused the agent to navigate to the user's own account settings, extract an email address, trigger a one-time password, open Gmail to read that code, and post both values to a public forum for an attacker to retrieve — the entire sequence completing in seconds with no visible sign to the user that anything had happened. Security researchers at LayerX documented a related technique nicknamed "CometJacking," where a single crafted link could turn Comet against its own user. Separately, researchers at Straiker showed a scenario where an innocuous-sounding email request to "organize our shared files" caused Comet's agent to instead delete contents from a connected Google Drive. Trail of Bits published a formal threat model of Comet earlier in 2026 concluding that indirect prompt injection isn't a bug specific to Perplexity's implementation but a structural weakness shared by the entire category of agentic browsers, because the same channel that carries legitimate webpage content to the model has no reliable way to distinguish it from an attacker's hidden instructions.
That last point is the one worth sitting with. This isn't a patchable flaw where a fix ships and the risk goes away. Even OpenAI's own chief information security officer has publicly described prompt injection as an unsolved frontier security problem, not a solved one with lingering edge cases. Layering a more capable model like Opus 4.6 into that same architecture doesn't close the gap — arguably it widens it, because a more capable reasoning engine executing a longer, more autonomous chain of actions gives a successful injection more to work with: more tabs it can navigate, more forms it can fill, more transactions it's trusted to complete without a human confirming each step. Perplexity's pitch is that better reasoning means Comet gets better at legitimate complex tasks. The uncomfortable flip side is that better reasoning, applied by an attacker's hidden instructions instead of the user's real ones, means the agent gets better at executing the wrong task convincingly too.
What this means for the "browser as the new OS" narrative
Comet's trajectory, alongside Personal Computer's expansion into local files, native apps, and voice control, is a concrete data point for a claim that's circulated all year: the browser is becoming the primary interface to a personal AI system, not just a way to view web pages. When an agent can read your local files, operate your email client, control your browser tabs, and take actions across all three from a single voice command, the meaningful unit of software isn't the individual app anymore — it's the orchestration layer sitting above all of them. That's a genuine platform shift, and it's why Perplexity, OpenAI with its ChatGPT Work and agent products, and Google's browser-integrated AI efforts are all racing toward some version of the same architecture roughly simultaneously. None of them are competing primarily on model quality anymore, which is precisely why Perplexity can afford to default to a rival's model without it feeling like a concession — the competition has already moved up a layer, to who owns the interface between the user's intent and the actions taken on their behalf.
That shift is also exactly why the security gaps matter more than they would have a year ago. An OS-level interface with unsolved injection vulnerabilities is a categorically bigger exposure than a chat window with the same flaw, because the blast radius includes everything the agent is trusted to touch: email, files, connected accounts, payment flows. Enterprises are already treating this as a governance problem rather than a wait-and-see one, given that agentic browsers are showing up on employee machines through personal accounts and free-tier access well ahead of any formal IT policy addressing them.
Practical takeaways for IT and security teams
- Inventory before you decide. Find out whether Comet or a comparable agentic browser is already installed on managed or BYOD devices in your environment before writing a policy — free, mainstream availability since late 2025 means adoption has likely outpaced any existing acceptable-use guidance.
- Treat "act on my behalf" permissions like privileged access, not a browser setting. Any agent that can complete transactions, submit forms, or read connected email should go through the same access review as a new integration or service account, with explicit scoping of what it's allowed to touch.
- Assume prompt injection is unsolved, not rare. Don't approve agentic browser use on the assumption that vendors will patch the vulnerability class away; build controls — network segmentation, transaction confirmation steps, monitoring for unexpected agent actions — that hold even if the underlying flaw persists indefinitely.
- Separate the model question from the risk question. A more capable model like Opus 4.6 improves task quality, but it does not reduce the injection attack surface — evaluate agentic browser risk based on what the agent is permitted to do in your environment, not which LLM happens to be running it that month.
- Pilot with irreversible actions disabled. If you allow agentic browsing at all, start with read-only or draft-only permissions — the agent can research and prepare, but a human confirms anything that sends money, deletes data, or submits a form — before considering broader autonomy.
- Revisit the policy every quarter, not annually. Both the model layer and the vulnerability research around agentic browsers are moving fast enough that guidance written in early 2026 will likely be stale by year's end.
Perplexity's decision to default Comet to a rival's model is a genuinely interesting strategic signal about where value is settling in the AI stack. But the more consequential fact sitting underneath it is that the browser doing the choosing still can't reliably tell the difference between its user's instructions and a stranger's, and no amount of model quality fixes that on its own.