OpenAI is facing simultaneous pressure on its security and governance practices, as researchers disclosed that its Atlas AI browser could be hijacked to spam users’ WhatsApp contacts while the U.S. Department of Justice imposed three years of oversight on the company’s green‑card sponsorship hiring.

A Browser That Can Turn Into a Worm

Security firm Zenity revealed at the Black Hat conference in Las Vegas that OpenAI’s Atlas web browser—an AI-enabled browser the company is shutting down next week—could have its protections bypassed and be manipulated into sending mass messages to a user’s WhatsApp contacts or making unauthorized Amazon purchases, despite having more safeguards than rival AI browsing tools.Wired

The attack chain exploited Atlas’s ability to act as an autonomous web agent: AI systems embedded in browsers can navigate sites, fill forms, and execute multi-step workflows, and in Atlas’s case, Zenity researchers demonstrated that these capabilities could be subverted into what they described as a “mass phishing campaign.”Wired

Zenity cofounder and CTO Michael Bargury said these AI-augmented browsers have weakened long-standing protections, arguing that vendors have “nerfed the security control of browsers,” bringing back attack patterns last seen two decades ago.Wired

How the WhatsApp spam attack worked

In one proof-of-concept, Zenity posted a newsletter sign-up link to X (formerly Twitter) and asked Atlas to register. The page hid Hebrew-language instructions telling the AI to open the user’s logged-in WhatsApp Web session and send every contact a message urging them to join the newsletter—a self-propagating phishing worm.Wired

The attack did not exploit a flaw in WhatsApp itself; instead, it circumvented multiple OpenAI safeguards by looking like a benign newsletter form, using Hebrew to evade English-focused safety filters, and falsely claiming that the environment was a sandboxed, fake version of WhatsApp rather than the user’s real account.Wired

Once triggered, Atlas would iterate through contacts and send the same instructions, effectively turning a single malicious page into a worm that “infects” friends and family with a phishing-style recruitment message.Wired

A wider pattern in AI browsing tools

Zenity’s Atlas findings were part of a broader survey of around 20 vulnerabilities across leading AI-enabled browsers and extensions from companies including Google, Anthropic, Microsoft, and Perplexity, enabling access to local machines, file exfiltration, password manager takeover, and full browsing-history leaks.Wired

Traditional browser defenses like the same-origin policy—which limits how websites can interact with each other—can become “effectively useless” when an AI agent is empowered to traverse domains and execute arbitrary instructions drawn from untrusted web content.Wired

OpenAI’s own security leadership previously labeled prompt-injection attacks against such agents an “unsolved security problem,” a warning now underscored by Zenity’s practical exploit against one of the better-defended products on the market.Wired

DOJ Steps In on Green‑Card Hiring Practices

On the same day the Atlas research became public, the Department of Justice’s Civil Rights Division announced a settlement placing OpenAI and its former subsidiary Statsig under three years of federal oversight for alleged discrimination against U.S. citizens in green-card sponsorship hiring.TechCrunch

The DOJ alleged that both companies used tactics designed to limit U.S. citizens’ ability to apply for positions held by immigrant workers whose permanent residence (PERM) sponsorship they were pursuing, in violation of the Immigration and Nationality Act (INA) requirement to genuinely seek qualified U.S. workers first.TechCrunch

Under the settlement, OpenAI and Statsig will pay $3.2 million, including a $1.2 million civil penalty and $2 million reserved as potential restitution for affected U.S. citizen applicants, while maintaining that they do not admit wrongdoing.TechCrunch

Allegations: making jobs hard to find—and harder to apply for

The DOJ said its investigation, launched in August 2025, covered five PERM-related cases at OpenAI between 2023 and 2025 and one at Statsig, which OpenAI acquired in September 2025 and partially divested in May 2026.TechCrunch

Although fewer than 10 roles were at issue, investigators claimed the companies used practices such as not listing PERM roles on public job boards, running radio ads late at night, and requiring paper rather than electronic applications—steps that tend to minimize the number of U.S. citizens who find and apply for such positions.TechCrunch

The settlement requires OpenAI and Statsig to draft PERM hiring policies subject to DOJ approval and submit semiannual reports detailing, among other things, how many foreign-worker applications they pursued and how many U.S. citizens they interviewed for those roles.TechCrunch

This case fits into a broader enforcement pattern: past administrations, including Biden’s, have used INA authority to police Big Tech hiring, with companies like Facebook and Apple entering similar settlements under allegations of more widespread violations.TechCrunch

Two Stories, One Theme: Trust Under Strain

Taken together, the Atlas security flaws and the PERM settlement highlight the dual vectors along which trust in AI companies is being tested: technical reliability and institutional integrity.

On the technical side, Zenity’s work shows that even comparatively cautious implementations of AI agents in browsers can be manipulated into actions that feel deeply personal—such as spamming one’s family and friends—despite multiple security boundaries.Wired

On the governance side, the DOJ’s oversight regime effectively places OpenAI’s sensitive immigration-related hiring decisions under continuing federal supervision, requiring documented proof that the company is offering U.S. workers a fair chance at roles tied to permanent residency.TechCrunch

In both domains, the underlying issue is whether a rapidly scaling AI lab can embed robust safeguards—technical and procedural—before its systems and employment practices cause wider harm.

Industry Impact: AI Labs Under the Microscope

For AI-enabled browsers and agents, Zenity’s findings will likely harden a growing consensus in the security community: that delegating complex, cross-site actions to AI systems revives long-solved browser risks and demands new, agent-specific defenses, not just recycled web security concepts.Wired

Other vendors named in Zenity’s research—Google, Anthropic, Microsoft, Perplexity—may face renewed scrutiny of their own products, especially where agents can access local files, password managers, or multi-account sessions, making them attractive targets for prompt-injection and data-exfiltration attacks.Wired

Regulators, meanwhile, are sending a clear signal that immigration-related compliance in the AI sector will not be treated as a secondary concern. The DOJ characterized this settlement as part of an “increased crackdown” on PERM abuses, drawing a straight line from prior actions against larger platforms to newer AI companies.TechCrunch

For OpenAI, the convergence of these stories deepens the stakes of its public reputation: it must convince users that its products can operate safely in adversarial environments and persuade regulators that its internal processes respect long-standing civil rights and immigration norms.

What to Watch Next

OpenAI is already in the process of shutting down Atlas, but Zenity’s demonstration will not retire with it; the techniques used against Atlas are broadly applicable to other AI browsing tools, and security researchers will almost certainly probe rival offerings with similar creativity.Wired

On the regulatory side, the next three years of DOJ oversight will generate a paper trail of OpenAI’s PERM-related hiring—semiannual reports, approved policies, and, potentially, restitution payouts—which could become a template for how civil-rights regulators supervise AI companies’ labor practices.TechCrunch

The long arc of technology governance suggests that industries stabilize only when both their tools and their institutions grow more resilient. In this moment, OpenAI finds itself tested on both counts—its browser agents and its hiring forms alike subject to a simple, ancient question: who do these systems truly serve?