On a Tuesday morning in early October, Perplexity did something Silicon Valley startups rarely do: it made its newest product completely free. Not freemium, not "free for now"—just free, full stop. The company's Comet browser, which had commanded $200 a month since its limited July launch, was suddenly available to anyone willing to download it.
The gesture was bold, maybe too bold. Within five weeks, Amazon's lawyers had fired off a legal threat over Comet's autonomous shopping features. Security researchers were circulating reports of vulnerabilities that could let malicious actors hijack the browser's AI assistant. And Perplexity found itself trying to explain how a tool designed to make the internet easier might actually make it more dangerous.
For a startup gunning for Google Chrome—which still holds roughly 68 percent of the global browser market—the timing was less than ideal.
The Ambition Behind Comet
Perplexity built Comet on Chromium, the same open-source foundation that powers Chrome, Edge, and most modern browsers. That means it looks familiar, supports the majority of Chrome extensions (with one telling exception: anything that messes with the new-tab page), and doesn't require users to relearn their muscle memory.
But familiarity isn't the point. Comet's selling proposition is the "Comet Assistant," an AI sidecar that can read web pages, summarize articles, compare information across multiple tabs, fill out forms, and execute tasks like booking meetings or completing purchases. You can tell it what you want in plain English—"schedule a meeting with Sarah next Tuesday" or "find the cheapest flight to Austin"—and it goes to work.
The browser runs on Windows 10 or later and macOS 11 or later. A mobile version was promised as "coming soon," though Perplexity's CEO recently warned users about counterfeit iOS apps cropping up in app stores. The official mobile release hasn't materialized yet.
When Perplexity opened Comet to the masses on October 2, it also launched a "Background Assistant" for subscribers paying $200 a month for its Max plan. Think of it as mission control for multiple simultaneous tasks running in the background. It sounds like the kind of feature that would delight power users—until you start thinking about what happens when things go wrong.
A Free Browser With a Complex Business Model
Giving away a browser is one thing. Making money from it is another. Perplexity is trying to thread that needle with a tiered subscription model that would make a telecom executive blush.
The browser itself costs nothing, though free users will eventually run into rate limits on AI queries. Comet Plus, at $5 per month, lifts those restrictions and includes a revenue-sharing arrangement that pays publishers 80 percent of subscription fees. Condé Nast signed on early, and Perplexity seeded the program with a $42.5 million fund to get publishers interested.
Step up to the Pro plan—$20 monthly—and you get Comet Plus alongside access to advanced AI models, image and video generation, and file analysis tools. The Max tier, at $200 a month, unlocks top-shelf AI models, email assistance, early access to experimental features, and that Background Assistant.
It's a sprawling structure, perhaps reflecting just how hard it is to monetize a free browser without resorting to ads or selling user data. Perplexity insists it stores data locally and doesn't train its AI on personal information. The company points to SOC 2 Type II certification and says it's GDPR and HIPAA compliant for enterprise customers.
Those assurances matter, of course. They matter less if the browser's most innovative features also happen to be its most exploitable.
When Automation Becomes a Liability

In September and October, security researchers from Brave and Guardio published audits that should give Comet users pause. The browser's AI assistant is vulnerable to indirect prompt injection—a technical term for a deceptively simple attack. Malicious code embedded in a web page can manipulate the AI into doing things the user never intended: triggering unauthorized purchases, leaking data to third parties, or setting up phishing attacks.
The very features that make Comet interesting—autonomous shopping, form autofill, cross-tab actions—also make it a target. It's one thing for a browser to passively display information. It's another for it to actively navigate sites and complete transactions on your behalf.
User complaints have trickled in on Reddit and other forums. Some mention performance lag, others point to compatibility issues with popular extensions like 1Password. A few describe a learning curve that undermines the whole productivity promise. Perplexity hasn't publicly addressed the security findings or announced patches, leaving early adopters to decide whether convenience outweighs risk.
Amazon Draws a Line
On November 4, Reuters broke the news that Amazon had sent Perplexity a legal threat. The issue: Comet's agentic shopping tool can autonomously complete purchases on Amazon's platform without going through Amazon's own checkout flow. Perplexity rejected the demand, calling it anti-competitive. Amazon responded that third-party tools risk degrading the customer experience—a claim that sounds defensive but isn't entirely unreasonable if Comet's automation is error-prone or susceptible to manipulation.
The standoff is less about technology than about control. Autonomous purchasing is appealing until an AI misinterprets a command or falls victim to a prompt injection attack. Who's liable when an AI agent racks up charges or ships the wrong items? The legal framework for assigning responsibility in these scenarios doesn't exist yet.
Perplexity is betting users will embrace this level of automation. Amazon is betting that outsourcing the checkout experience to a third-party browser is a risk it won't tolerate. Neither side is obviously wrong.
Unconventional Partnerships

Perplexity has pursued distribution partnerships with the kind of eclecticism you don't usually see in browser launches. PayPal and Venmo offered early access in September, bundling a 12-month Perplexity Pro trial with priority waitlist spots. Chess.com—yes, Chess.com—ran a promotion from early October through the start of November, dangling 30 days of Premium membership and a $200,000 "Comet Open" tournament to anyone who downloaded the browser.
Rumble, the video platform popular with conservative audiences, announced a strategic partnership on October 2. The deal bundles Perplexity Pro with Rumble's service and commits ad spend to promote Comet. Squarespace integrated website-building workflows directly into the browser. Perplexity is also reportedly talking to phone manufacturers about preinstalling Comet on mobile devices, though no deals have been finalized.
On the enterprise side, Perplexity launched a Pro tier with single sign-on, admin controls, and compliance features. It's aimed at businesses wary of consumer-grade tools that don't meet corporate security standards. Whether enterprises will adopt a browser that security researchers have flagged remains to be seen.
Scale, Speed, and the Guardrails Question

There's something genuinely interesting about what Perplexity is trying to do. Comet isn't just Chrome with a chatbot bolted on—it's an attempt to reimagine browsing in an AI-native world. The partnerships are real, the features are ambitious, and making it free shows the company understands it needs scale to compete with Google.
But the security vulnerabilities and the Amazon dispute suggest Perplexity may have moved faster than its infrastructure could handle. A browser that acts on your behalf is powerful. It's also dangerous if the guardrails aren't solid, and right now, those guardrails look more aspirational than actual.
Perplexity promised millions on the waitlist that Comet "will always be free." Whether it can keep that promise depends on whether it can solve problems that aren't purely technical—legal exposure, user trust, and the small matter of convincing people to switch from a browser that already works.
For now, Comet is free. Whether it stays that way, or stays safe, is a different question entirely.
