Google now has two closely related ways to let Gemini act on the web: Gemini Spark and Chrome auto browse.

They overlap enough to be confusing, but the useful distinction is simple:

  • Chrome auto browse is a browser-level agent that works inside Chrome to complete multi-step web tasks on the current computer.
  • Gemini Spark is a broader persistent agent inside Gemini that can manage tasks and schedules across connected apps, files, Google services, a remote browser, and—when available—local Chrome through auto browse.

That difference changes what happens when the computer closes, which accounts can use the feature, what data the agent can reach, and which product is better for a given job.

Feature and pricing check: August 8, 2026. Google says both features are experimental and still rolling out. Availability, quotas, plan names, and prices can change. The public U.S. Google One plans page currently lists Google AI Pro at $19.99/month with 5 TB of storage. Google AI Ultra has multiple usage/storage tiers and market-dependent pricing, so readers should verify the price shown in their own Google One checkout rather than assume one global number.

The quick comparison

QuestionChrome auto browseGemini Spark
Main jobComplete a multi-step task on websitesManage longer-running tasks, workflows, schedules, apps, files, and web actions
Where it startsGemini in desktop ChromeGemini web app, Gemini mobile app, or Gemini app on Mac
Local browser accessYesYes, by connecting to Chrome auto browse when supported
Remote browserNot the main execution modelYes
Can continue after the local computer closes?No for the local Chrome taskOften yes if Spark can continue in its remote browser; some steps may still wait for human input
Schedules / recurring tasksNo general Spark-style schedulerYes
Connected Google appsCan use relevant Gemini context and servicesCan use supported Workspace apps, Search services, YouTube and selected third-party apps
Personal Google AccountRequired for consumer auto browseRequired; work/school accounts are not currently supported for Spark
Current geographic availabilityU.S. onlyBroader, but Google currently excludes the EEA, Nigeria, Switzerland and the UK
Current paid-plan requirementGoogle AI Pro or UltraGoogle AI Pro or Ultra, subject to regional rollout
Published task limitsPro: up to 20 multi-step requests/day; Ultra: up to 200/dayCompute-based limits; up to 15 tasks can be running at once

The important point is that Spark can use auto browse, but auto browse is not Spark.

What Chrome auto browse actually does

Chrome auto browse lives closest to the browser itself.

A task begins from the Ask Gemini interface in desktop Chrome. Gemini creates a plan, shows it for review, and then opens or uses tabs to carry out steps such as:

  • comparing products across sites;
  • searching for travel options;
  • adding items to a cart;
  • making restaurant reservations;
  • scheduling appointments;
  • finding tickets;
  • collecting receipts or other administrative information.

Google says the feature can choose websites on its own, work across tabs, and ask for confirmation or hand control back to the person when a sensitive step appears.

That makes auto browse useful for a task that sounds like:

Find three refundable hotels near this venue for these dates, compare total prices, and stop before booking.

The unit of work is essentially a browser task happening now.

It can use logged-in sites

With permission, Gemini in Chrome can act on websites where the browser already has access. Google also documents an optional integration with Google Password Manager that can help Gemini sign in to allowed sites.

Google says Password Manager does not hand the raw password to Gemini. The user grants site-level permission, and that permission can later be removed in Password Manager settings.

This convenience is also why the risk model matters: a browser agent operating inside a signed-in session can potentially reach more sensitive information than a normal chatbot tab.

What Gemini Spark adds on top

Spark is designed around a different abstraction: a task that may continue for a while, use several tools, and run again later.

Google describes Spark as a personal AI agent for complex workflows and schedules. A Spark task can use information from supported sources including:

  • Gmail, Calendar, Docs, Drive, Sheets, Slides, Keep and Tasks;
  • Google Search, Finance, Flights, Hotels and Maps;
  • YouTube;
  • supported third-party connected apps such as Canva, Dropbox, Instacart, OpenTable and Zillow;
  • uploaded files;
  • reusable skills;
  • schedules;
  • a remote browser and remote computer;
  • local Chrome when auto browse is available and permission is granted.

That makes Spark better suited to a request such as:

Every weekday morning, check these sources, update this document, and flag anything that needs attention.

The difference is not that Spark is “smarter.” The difference is that Spark has a longer-lived workflow model.

The biggest practical difference: what happens when the computer closes?

This is where the two products diverge most clearly.

When Spark connects to the local Chrome browser, Google says the computer and Chrome need to stay awake and running while that local-browser work continues.

If the computer becomes unavailable, Spark may switch to a remote browser instead. That remote browser is a separate browser instance, not a cloud copy of the local Chrome session.

A remote Spark task can therefore continue after the local device is closed.

However, there is an important limitation: if the remote browser reaches a login page, payment step, verification challenge, or another action that requires human input, Spark may stop and wait for the person to take over.

So the practical rule is:

  • Need the agent to use the exact logged-in state of the current Chrome browser? The computer must remain available.
  • Need a task to keep progressing while the computer is away? Spark's remote browser is the more relevant execution path, but it may not inherit every local login and can still pause for sensitive steps.

Local browser versus remote browser

The terminology is easy to mix up, so it helps to think of two separate machines.

Local Chrome

This is the Chrome installation already running on the computer.

Advantages:

  • already signed in to websites;
  • can use the current tabs and browser state;
  • can use approved Password Manager sign-in flows;
  • easy to watch and take over immediately.

Trade-offs:

  • the device and Chrome need to remain awake for the task;
  • the agent potentially has access to sites that are already authenticated;
  • browsing actions occur in a browser that may contain sensitive personal sessions.

Spark remote browser

This is a separate browser running remotely for the task.

Advantages:

  • the task can continue when the local machine is closed;
  • it separates the automation environment from the everyday browser;
  • it is better suited to longer-running or scheduled work.

Trade-offs:

  • it may not already be authenticated to every site;
  • some login or confirmation steps require human takeover;
  • Google stores some remote-browser data, including cookies used for future sessions, until it is deleted or automatically cleared.

Google provides controls in Spark settings to delete saved remote-browser data and remote code-execution data.

Availability is not the same for both products

This is one of the easiest details to miss.

Chrome auto browse

Google's current consumer support page says auto browse requires:

  • age 18 or older;
  • the United States;
  • a personal Google Account;
  • desktop Chrome with the latest version;
  • English as the device language;
  • Google AI Pro or Google AI Ultra;
  • Safe Browsing set to Standard or Enhanced protection.

The feature is still rolling out, so meeting those conditions does not guarantee it will already appear on every account.

Google currently says auto browse is not available in Gemini in Chrome on iPhone or iPad.

Gemini Spark

Google's current Spark support page says Spark requires:

  • age 18 or older;
  • a personal Google Account;
  • Google AI Pro or Ultra;
  • Gemini Apps activity turned on.

Google currently lists Spark as unavailable in:

  • the European Economic Area;
  • Nigeria;
  • Switzerland;
  • the United Kingdom.

It is available through the Gemini web app, Gemini mobile app and Gemini app on Mac where the rollout is supported.

That creates an odd but important distinction: Gemini in Chrome itself has broad international availability, while the specific auto-browse agent feature remains U.S.-only, and Spark has its own separate country exclusions.

The quotas are different too

Google publishes a simple daily limit for Chrome auto browse:

  • Google AI Pro: up to 20 multi-step requests per day;
  • Google AI Ultra: up to 200 multi-step requests per day.

Spark does not use that same simple daily counter for all work. Google describes Spark as having compute-based usage limits that depend on task complexity and plan level.

It also says a Spark account can have up to 15 tasks running at the same time. If 15 are already running, another task or scheduled run has to wait until capacity becomes available.

That distinction matters when comparing plans. A browser automation that consumes one auto-browse request is not necessarily equivalent to one long Spark workflow.

Which should be used for which task?

A useful decision framework is to ask three questions.

1. Does the task need the current browser session?

Use Chrome auto browse when the job depends heavily on websites already open or signed in on the current computer.

Examples:

  • compare products using an existing shopping account;
  • find a receipt inside a logged-in service;
  • fill a form using a website that is already authenticated;
  • make a reservation while watching each step.

2. Does the task need to run later or repeatedly?

Use Gemini Spark when the job is better described as a workflow than a browsing session.

Examples:

  • monitor a topic on a schedule;
  • summarize inbox changes each morning;
  • update a document from several sources;
  • coordinate actions across Gmail, Calendar, Drive and the web;
  • run a recurring research task.

3. Would a mistake be expensive or difficult to reverse?

Use neither in fully hands-off mode for a high-risk action.

Google itself warns that agentic features are experimental and may make mistakes. Purchasing, sending communications, editing important data, submitting forms, handling payment information, or interacting with sensitive accounts should remain supervised.

The privacy question is really an access question

The biggest privacy change with an agentic browser is not that the model can generate text. It is that the model can act inside authenticated systems.

Google explicitly warns that Spark and Chrome auto browse may share information with websites when that information is needed to complete a task. Depending on the connected services and task, that can include names, contact information, preferences, files, or other sensitive data.

Spark may also use connected Workspace data and Personal Intelligence when those features are enabled.

The practical safety rule is therefore to minimize the agent's authority:

  1. connect only the apps needed for the task;
  2. review the proposed plan before starting;
  3. avoid putting passwords or payment details directly into a task prompt;
  4. take over the browser for sensitive authentication steps;
  5. remove site sign-in permissions that are no longer needed;
  6. clear remote-browser data after sensitive work;
  7. stop a task immediately if it begins visiting irrelevant sites or requesting unrelated data.

This is more useful than asking whether an agent is simply “safe” or “unsafe.” The risk depends heavily on what it can access and what actions it is allowed to take.

Prompt injection is the hard problem both products share

A browser agent reads websites, emails and documents while deciding what to do next. Those sources can contain instructions that were not written for the agent's legitimate task.

Google's support documentation explicitly calls out prompt injection: malicious or misleading instructions hidden in content that attempt to redirect the agent.

For example, a compromised page could contain text telling an agent to upload data somewhere else, send a message, or run an unrelated action.

Google says it uses confirmations, action restrictions, takeover flows and other safeguards to reduce this risk. It also says those protections do not guarantee that every attack or mistake will be stopped.

The consequence is straightforward: the more powerful the agent becomes, the more important it is to treat websites as untrusted input, not merely as pages to summarize.

A five-minute setup checklist

Before handing over a real task, use one low-risk test.

For Chrome auto browse

  1. Confirm the account is eligible and auto browse appears in desktop Chrome.
  2. Open a harmless task such as comparing three public products or restaurants.
  3. Review Gemini's proposed sites and plan before clicking Start Task.
  4. Watch how it switches tabs and where it asks for confirmation.
  5. Test the Take over task control.
  6. Check the Gemini-in-Chrome permission toggle under Chrome's AI settings.

For Spark

  1. Open Spark and create a non-sensitive task with no private connected apps.
  2. Check the work panel to see planned and completed steps.
  3. Run the task once in a remote browser.
  4. If local Chrome integration is available, compare the same task using local Chrome.
  5. Review Spark's browser-data deletion controls.
  6. Only after that test, connect the minimum Google apps needed for a real workflow.

The purpose is not to test whether the AI gives a clever answer. It is to learn where the agent acts, when it asks permission, and how easily the task can be stopped.

So which one is the bigger change?

Chrome auto browse makes the browser itself more capable. It turns Gemini from a side-panel assistant into software that can navigate and act across websites.

Spark is the larger architectural change because it treats the browser as only one tool in a persistent workflow. The same task can combine schedules, connected apps, files, search, code execution and browser actions.

That is why the products can coexist:

  • auto browse is the browser executor;
  • Spark is the workflow orchestrator that can call a browser executor when needed.

For a one-off web chore, Spark may be unnecessary. For a recurring process that touches several services, auto browse alone may be too narrow.

What to watch next

Three changes will matter most over the next few releases.

Wider country availability

Auto browse remains U.S.-only, while Spark still excludes several major markets. Expansion would materially change who can use these workflows outside testing and early-adopter groups.

Better permission scoping

The most valuable safety improvement would be finer control over which sites, folders, accounts and actions an agent can use for each task rather than broad access inherited from a signed-in browser.

Clearer task accounting

As agentic plans become usage-metered, people will need a better way to predict whether a workflow consumes one request, many requests, or a large amount of compute.

For now, the best way to choose between the products is not to ask which one is more powerful. Ask where the task should run, how long it should live, and how much access it genuinely needs.

Conclusion

Gemini Spark and Chrome auto browse are two layers of the same agentic direction, but they solve different problems.

Chrome auto browse is best understood as a browser operator for multi-step tasks on the current computer. Gemini Spark is a longer-lived task manager that can use many tools—including local Chrome, a remote browser, connected apps and schedules.

The practical dividing line is persistence. If the work is a browser session happening now, auto browse is the simpler tool. If the work needs to continue, repeat, coordinate several services, or survive beyond one browsing session, Spark is the more relevant model.

In both cases, the most important feature is not autonomy. It is the ability to see the plan, restrict access, take control, and stop the agent when the task moves outside its intended boundary.

Sources

Checked August 8, 2026:

Written and reviewed by /lico

Just writing down my thoughts, interests, and the things I learn along the way.