All Articles
Updated (originally published )41 min read

The Agentic Browser Landscape in 2026: A Complete Guide

Agentic BrowsersChromeAI AgentsModel Context ProtocolAXO
AUTHOR
Slobodan "Sani" Manic

Slobodan "Sani" Manic

No Hacks

CXL-certified conversion specialist and WordPress Core Contributor helping companies optimise websites for both humans and AI agents.

No Hacks runs no sponsorships and is funded by advisory and audit work.

The browser is no longer just a window to the web. It's becoming an AI agent that browses on your behalf.

In the space of 15 months, we've gone from Anthropic demonstrating computer use as a research preview to Google building agentic features into the world's most popular browser. Every major tech company now has some form of AI-powered browser automation, whether as a consumer product, developer tool, or enterprise API.

This is the complete guide to the agentic browser landscape as of July 2026. It expands on the timeline I presented in my "The Jungle of Optimizing for AI Agents" keynote at Conversion Hotel.

Updated September 8, 2026: The Ninth Circuit ruled in Amazon v. Perplexity on August 4, vacating the injunction and holding that the user, not Perplexity, accesses Amazon under the CFAA. Amazon has petitioned for rehearing en banc. ChatGPT Atlas shut down on August 9. Mozilla's AI Window arrived as Smart Window. Anthropic released a browser inside Claude Cowork and took Claude in Chrome to general availability without per-action approval. Opera Neon added a free plan. WebMCP reached a second browser engine and its first mainstream agent client. Four new agentic-browser attacks were disclosed, and the EU AI Act's transparency duties became applicable.

Updated July 31, 2026: OpenAI is retiring the standalone ChatGPT Atlas browser (announced July 9, shutdown August 9), moving agentic browsing into the ChatGPT desktop app and a Chrome extension. Chrome auto browse went live on Android in late June. WebMCP entered origin trial in Chrome 149. Microsoft retired the Copilot Mode brand and folded AI directly into Edge. Added the June 11 Ninth Circuit oral arguments in Amazon vs Perplexity, the University of Washington security study, Firefox's opt-in AI Window, and Safari's first agentic feature from WWDC 2026.

Updated June 1, 2026: Google announced Chrome auto browse is coming to Android at the OS level, arriving on Pixel 10 and Galaxy S26 in late June 2026 with a stated rollout to 200 million devices by year end. Moved the Amazon vs Perplexity Ninth Circuit hearing to its June 11 date and linked the dedicated breakdown of the case. Added Cloudflare's agent-readiness scanner to the practical checklist.

Updated May 1, 2026: Added Cloudflare Browser Run rebrand and WebMCP support, Amazon vs Perplexity April appeal updates and May 15 hearing date, and Microsoft Edge Copilot redesign.

Updated April 2, 2026: Added Google-Agent user agent and Web Bot Auth, Samsung Browser with Perplexity AI, Claude for Chrome Quick Mode, Prisma Browser for agentic security, OpenAI Operator shutdown and Instant Checkout abandonment, Amazon vs Perplexity injunction ruling, Chrome Gemini 3 side panel and Connected Apps, Comet enterprise rollout, and agentic browser security vulnerabilities.

Updated March 5, 2026: Added Google WebMCP early preview, Perplexity Comet iOS launch, Opera Neon Intelligent Mode, Stagehand v3, and the Amazon vs Perplexity lawsuit.


GET WEEKLY WEB STRATEGY TIPS FOR THE AI AGE

Practical strategies for making your website work for AI agents and the humans using AI to find you. Once a week you get the new articles, the latest podcast episode, and a few links worth keeping.

Contents

Timeline: The Rise of Agentic Browsers

The agentic browser went from research demo to mass-market consumer product in roughly fifteen months:

DateMilestone
Oct 2024Anthropic launches Computer Use public beta
Nov 2024Anthropic releases Model Context Protocol (MCP)
Dec 2024Google announces Project Mariner research prototype
Jan 2025OpenAI launches Operator with Computer-Using Agent
Mar 2025Amazon introduces Nova Act browser automation SDK
Mar 2025Microsoft releases Playwright MCP
Apr 2025Microsoft announces Copilot Studio Computer Use
May 2025Genspark launches AI browser with on-device models
Jun 2025The Browser Company launches Dia with AI features
Jul 2025Perplexity launches Comet browser
Jul 2025Microsoft releases Edge Copilot Mode
Aug 2025Anthropic releases Claude for Chrome preview
Aug 2025OpenAI shuts down Operator on August 31, its functionality absorbed by ChatGPT agent
Sep 2025Opera launches Neon agentic browser
Sep 2025Atlassian acquires The Browser Company
Oct 2025OpenAI launches ChatGPT Atlas browser
Nov 2025Manus Browser Operator launches for Chrome and Edge
Dec 2025Google debuts Disco experimental AI browser
Jan 2026Chrome rolls out Gemini auto browse to all users
Feb 2026Google releases WebMCP early preview in Chrome Canary
Feb 2026Opera Neon adds Intelligent Mode with automatic agent selection
Feb 2026Stagehand v3 launches, 44% faster with AI-native rewrite
Mar 2026Perplexity Comet launches on iOS, completing cross-platform rollout
Mar 2026Chrome moves to 2-week release cycle in response to agentic browser competition
Mar 2026Amazon wins preliminary injunction against Perplexity Comet
Mar 2026Chrome Gemini 3 gets side panel, Connected Apps, and image generation
Mar 2026Google adds Google-Agent to official user-triggered fetchers list
Mar 2026Palo Alto Networks unveils Prisma Browser for agentic AI security
Mar 2026Samsung Browser launches on Windows with Perplexity-powered agentic AI
Apr 2026Cloudflare renames Browser Rendering to Browser Run and adds WebMCP support
Apr 2026Perplexity files its appeal to lift the Comet ban in the Amazon CFAA case, and the Ninth Circuit later sets the hearing for June 11
Apr 2026Microsoft confirms Edge Copilot UI redesign, Canary now, stable rollout from June 2026
May 2026Google announces Chrome auto browse coming to Android at the OS level (Pixel 10, Galaxy S26) in late June 2026
May 2026Microsoft retires the Copilot Mode brand and folds AI features directly into Edge
Jun 2026Apple launches agentic password management in Safari at WWDC 2026
Jun 2026WebMCP enters origin trial in Chrome 149
Jun 2026Ninth Circuit hears oral arguments in Amazon vs Perplexity
Jun 2026Gemini in Chrome arrives on Android with auto browse on Pixel 10 and Galaxy S26
Jul 2026OpenAI announces Atlas retirement, and the browser stops working August 9
Aug 2026EU AI Act Article 50 transparency obligations become applicable (August 2)
Aug 2026Ninth Circuit vacates the injunction against Perplexity Comet, holding the user does the accessing (August 4)
Aug 2026Zenity Labs expands PleaseFix to five named browser agents, and discloses Grand Theft Atlas
Aug 2026ChatGPT Atlas stops working (August 9)
Aug 2026Opera Neon adds a free plan and becomes an MCP server other agents can drive (August 14)
Aug 2026Mozilla releases Smart Window, the renamed AI Window, in beta (August 18)
Aug 2026Gemini in Chrome reaches all US Android users, while auto browse stays US-only and paid (August 18)
Aug 2026Anthropic takes Claude in Chrome to general availability and releases a browser inside Claude Cowork (August 26)
Aug 2026OpenAI adds WebMCP support to ChatGPT, the first mainstream agent client to call site tools
Sep 2026Firefox 155 opens Smart Window to the USA, Canada and France (September 1)

The pace is accelerating. What started as research demos became developer tools, then consumer products.

Consumer AI Browsers

Regular users can download and use these agentic browsers today. They split into two categories: standalone AI-native browsers like Perplexity Comet and Opera Neon, and AI features added to existing browsers like Chrome's Gemini and Edge's built-in AI. The standalone category is thinning: ChatGPT Atlas shut down on August 9, 2026, and its story below explains why.

Standalone AI Browsers

Perplexity Comet

Perplexity's entry into the browser market came in July 2025. Comet combines their search-focused AI with full browser capabilities. You can ask questions naturally, and the browser handles the research, visiting multiple websites and synthesizing information.

The agentic features go beyond search. Comet can fill forms, compare products across websites, and complete basic transactions. It's free, which makes it the most accessible entry point for users curious about agentic browsing.

In March 2026, Comet launched on iOS, completing its cross-platform rollout (desktop in July 2025, Android in November 2025, iOS in March 2026). The app is a free download, with Perplexity Pro and Max subscriptions available for power users.

Comet also expanded to enterprise customers in March 2026, with Comet Assistant offering in-page research, summarization, and autonomous multi-step tasks like booking flights, managing email, and filling forms. Enterprise administrators can deploy Comet silently across macOS and Windows devices via MDM.

ChatGPT Atlas (OpenAI) - shut down August 9, 2026

OpenAI launched Atlas in October 2025 as a dedicated browser product. The key feature was Agent Mode, which allowed the browser to execute multi-step tasks autonomously. Ask it to "find and compare flight prices to Tokyo for next month," and it opened tabs, navigated airline websites, extracted pricing, and presented a comparison.

The experiment lasted 292 days. On July 9, 2026, OpenAI announced it was retiring Atlas, and the standalone browser stopped working on August 9, 2026. Bookmarks, tabs and history did not migrate. The agentic browsing capabilities survived: OpenAI moved them into the ChatGPT desktop app, the ChatGPT Chrome extension and Codex, per its own migration guidance. The extension was not built for this. It already existed with two million users when Atlas was announced, and absorbed the role. OpenAI's stated reason is consolidating fragmented interfaces into a single ChatGPT app, though the company has not shared usage or cost figures for Atlas. I wrote about why the standalone AI browser was the wrong shape from the start in AI Browsers Are Backward Because Agents Never Needed the Visual Layer.

Atlas was the second agentic product OpenAI retired. The Computer-Using Agent technology behind it first appeared in Operator, released as a research preview on January 23, 2025. OpenAI deprecated Operator on July 17, 2025, saying ChatGPT agent had absorbed its core functionality, and its release notes, since deleted, set the shutdown for August 31, 2025. OpenAI framed both retirements as consolidation rather than failure, and has never published usage or cost figures for either. OpenAI also killed Instant Checkout, the in-chat purchasing feature launched with Etsy, Shopify, and Stripe in September 2025. After six months, users were researching products in ChatGPT but not completing purchases, and OpenAI hadn't built a system for collecting state sales taxes. The company pivoted to partnering with retailers to create dedicated apps within ChatGPT that reroute users to the retailer's own website to complete transactions.

Dia (The Browser Company / Atlassian)

Dia launched in mid-2025 from The Browser Company, the team behind Arc. The browser was designed from the ground up with AI assistance at its core, not bolted on afterward.

Things changed on September 4, 2025, when Atlassian announced it was acquiring The Browser Company for about $610 million. The deal closed on October 20, 2025, and Atlassian's own filings show the final consideration was roughly $488 million in cash plus stock subject to vesting, so the widely quoted all-cash figure describes the announcement rather than the closing. The announcement framed Dia as becoming "the browser optimized for knowledge workers."

Dia is generally available today as a direct download on macOS 14 or later with Apple Silicon, with a paid tier and a fourteen-day trial. Windows is beta-waitlist only, with the website promising autumn 2026. Arc, the company's earlier browser, is now in maintenance mode: its own homepage tells visitors that "Arc receives Chromium updates only" and points them to Dia for active security patches.

Fellou

Fellou differentiates itself through transparency and control. Where other agentic browsers operate as black boxes, Fellou lets you visually inspect and edit its planned workflow before execution. You can intervene at any step, which addresses a common concern about autonomous agents taking unintended actions.

The browser handles logged-in sessions across platforms like Salesforce, LinkedIn, and Reddit, making it practical for research workflows that require authenticated access. Its "agentic memory" feature learns from your browsing history and notes to provide contextual assistance without repeated prompting.

Genspark

Genspark launched in May 2025 with a distinctive proposition: on-device AI models that run locally without internet connectivity. The browser includes over 169 open-weight models from providers like OpenAI, Google, and Meta, all running on your machine rather than in the cloud.

The agentic capabilities include Autopilot Mode for autonomous browsing and a Super Agent that can make phone calls, book reservations, and draft emails based on your calendar. Genspark also features an MCP Store with over 700 tool integrations. The company raised $160 million and reached a $530 million valuation, though a September 2025 security analysis flagged concerns about its vulnerability to compromised web pages.

Sigma AI Browser

Sigma AI Browser takes a privacy-first approach to agentic browsing. Its SigmaGPT assistant runs locally by default, with no tracking or cloud dependency. The browser offers full agentic capabilities including logging into websites, filling forms, extracting data, and executing multi-step tasks.

What sets Sigma apart is accessibility: the agentic features are completely free, and the browser runs on Windows, macOS, Linux, Android, and iOS. For users who want to experiment with agentic browsing without subscriptions or waitlists, Sigma provides a low-barrier entry point.

Samsung Browser

Samsung Browser launched on Windows in March 2026, extending Samsung's mobile browser to desktop with a Perplexity-powered AI assistant built in. The assistant understands natural language, the context of the page being viewed, and activity across tabs, making it the first OEM browser to ship with agentic AI from a third-party provider.

The cross-device angle is the differentiator. Samsung Browser syncs browsing sessions between Galaxy phones and Windows PCs, so a research task started on mobile carries over to desktop. Samsung had already integrated Perplexity's APIs at the platform level with Galaxy S26, where Bixby uses Perplexity for real-time web search. Agentic features are currently available in South Korea and the United States.

AI Features in Existing Browsers

Chrome + Gemini

Google's biggest move came January 28, 2026, with Chrome auto browse. The feature, powered by Gemini 3, turns Chrome into an autonomous agent that can scroll, click, type, and navigate on your behalf.

Auto browse is available to Google AI Pro and AI Ultra subscribers in the US. Given Chrome's 3 billion user base, this represents the largest deployment of agentic browser technology to date. I wrote about the implications for website owners in Chrome Just Became an AI Agent.

On May 12, 2026, Google went further and announced that auto browse is coming to Android at the operating-system level. The rollout began at the end of June as announced: Gemini in Chrome on Android covers select US devices running Android 12 or newer with at least 4GB of RAM and the device language set to US English. Auto browse on Android requires a Google AI Pro or Ultra subscription, started with Pixel 10 and Galaxy S26, and is expanding toward a stated 200 million devices by the end of the year. On August 18, 2026, Gemini in Chrome reached all Android users in the US, moving past the initial Pixel 10 and Galaxy S26 devices. Auto browse itself did not widen: it is still limited to Google AI Pro and Ultra subscribers in the US. Worth keeping those separate, because headlines routinely conflate three different things. Gemini Spark went international, Gemini in Chrome expanded, and auto browse did neither.

The agent comes baked into Android rather than as a downloadable app or browser extension. OS-level integration gives the agent system-level permissions and default availability on hundreds of millions of phones, which puts it in a different category from any other agent product on the market today. A booking that breaks when JavaScript is disabled is a booking the agent cannot complete. I covered what this shift means for website owners in Chrome auto browse comes to Android.

In March 2026, Chrome added a Gemini side panel available on any tab, Connected Apps integration (Gmail, Calendar, YouTube, Maps, Google Shopping, Google Flights), and image generation powered by Nano Banana. The side panel turns Chrome into a persistent AI workspace, not just a browsing tool with occasional AI assistance.

On the infrastructure side, Google added Google-Agent to its official list of user-triggered fetchers on March 20, 2026. This new user agent identifies requests from AI agents running on Google infrastructure, including Project Mariner. Unlike Googlebot, Google-Agent only activates when a human directs an AI assistant to perform a task, and it ignores robots.txt because Google treats it as a user proxy rather than a crawler. Google is also experimenting with Web Bot Auth, a cryptographic identity protocol, using the identity https://agent.bot.goog. I wrote about the implications in Google-Agent: The Web's New Visitor Just Got an Identity.

Google Disco

While Chrome got Gemini integration, Google's more experimental work is happening in Disco, a separate browser launched in December 2025 through Google Labs.

Disco takes a different approach. Rather than adding AI to traditional browsing, it generates custom web applications from your open tabs. The feature, called GenTabs, analyzes what you're working on and creates interactive tools to help. Planning a trip? Disco builds a custom travel planner with maps and booking links. Researching a topic? It generates a structured dashboard pulling from all your sources.

The browser removes the traditional URL bar entirely, replacing it with a prompt composer. It's currently waitlist-only and macOS-only, serving as Google's testing ground for ideas that may eventually reach Chrome.

Microsoft Edge (formerly Copilot Mode)

Microsoft launched Copilot Mode for Edge in July 2025. The feature differentiated itself with multi-tab context awareness: Copilot could see all your open tabs, understanding the full context of what you were researching to provide better assistance.

In April 2026, Microsoft confirmed an Edge UI redesign aligning the browser visually with the broader Copilot and Bing systems. The redesign turned out to be the endgame for Copilot Mode as a separate product. On May 13, 2026, Microsoft retired the Copilot Mode brand entirely and built its capabilities (multi-tab reasoning, screen analysis, voice and vision controls) directly into Edge's core interface on desktop, Android, and iOS.

The dedicated sidebar was replaced by an AI icon and a floating command bar, Edge gained a privacy dashboard that logs AI queries, and a single toggle disables all AI features for users who want none of it. The AI features remain free. Ten months after Copilot Mode launched as an opt-in experiment, AI assistance became the default posture of the browser itself.

Claude in Chrome

Anthropic's approach differs from the others. Rather than building a full browser, they released Claude in Chrome as an extension that brings Claude's capabilities directly into your existing browser.

The extension launched in August 2025 as a limited preview for Max plan subscribers, expanding to Pro, Team, and Enterprise plans in December 2025. It can take actions on websites, fill forms, and integrate with Claude Code for debugging workflows.

Claude in Chrome puts significant emphasis on security, with website-level permission controls and action confirmations for sensitive operations. Anthropic published their work reducing prompt injection attack success rates from 23.6% to 11.2%. A zero-click vulnerability was disclosed via HackerOne in December 2025 and fully patched by February 2026, with users urged to update to version 1.0.41 or later.

In March 2026, Anthropic added Quick Mode, an experimental fast browsing experience that makes the extension 3x faster by bypassing the standard tool-use protocol and replacing it with a compact single-letter command language. Max subscribers can choose between Sonnet 4.5 and Opus 4.6 for complex tasks.

Two things changed in August 2026. On August 12 the side panel became a full Claude Cowork session, with skills, connectors and cross-device handoff, acting on the live authenticated page. Then on August 26 Claude in Chrome went generally available on every paid plan, and the approval model changed: instead of asking before each action, a safety classifier validates actions and Claude proceeds autonomously. That moves the human checkpoint from the user to the vendor's own filter, which is a meaningful shift in who is responsible when an agent does something the user did not intend. It remains Chrome desktop only, with no support for other Chromium browsers or mobile.

The same week, Anthropic went the other way as well and built a browser into the Claude Cowork desktop app. When a task needs a website, a browser opens in a side panel and Claude navigates it directly. It is deliberately separate from your own browser and your own logins, which makes it the one genuinely new agent-owned browser of the period, and it came from a model vendor rather than a browser vendor.

Brave Leo

Brave's Leo AI assistant has been around since 2023, offering chat capabilities, page summarization, and content generation. It's a conversational tool, not an autonomous agent. Leo remains free for basic use, with premium tiers for more capable models.

Opera AI

Opera upgraded its built-in AI in October 2025, but the focus remains on assistance rather than automation. You can chat with pages and get summaries, but Opera doesn't offer the autonomous browsing capabilities of competitors. The AI features are free.

Opera Neon

Opera's experimental work happens in Opera Neon, a separate browser that launched in September 2025 and went public in December at $19.90 per month.

Unlike Opera AI's conversational assistant, Neon is built for autonomous action. It includes four specialized agents: Neon Do for web automation tasks, Neon Make for generating code and creative content, ODRA for deep research, and a standard chat interface. The browser integrates leading models including Gemini 3 Pro and GPT-5.1.

Opera positions Neon as its testing ground for agentic features before they reach mainstream products. Some of Neon's underlying architecture has already made its way into Opera One, delivering 20% faster AI responses.

In February 2026, Neon added Intelligent Mode, which automatically suggests the right agent (Chat, Do, Make, or 1 Minute Research) based on user intent. Instead of manually selecting which agent to use, the browser analyzes what you're trying to accomplish and routes you to the appropriate tool.

On August 14, 2026, Opera made Neon free to use as an agent target. The Free plan connects Neon to an existing agentic setup, including as an MCP server. The paid Standard plan is only needed to use Neon's own AI. That inverts the usual pitch. Neon stops being the agent you use and becomes the browser your agent drives, which makes it the first mainstream browser sold as infrastructure for somebody else's agent.

Consumer Browser Comparison

BrowserAgentic FeaturesFree TierPlatform
Perplexity CometFullYesDesktop, Android, iOS
ChatGPT AtlasDiscontinued-Shut down August 9, 2026
Chrome + GeminiFull (auto browse)LimitedBuilt into Chrome (desktop, Android)
Edge (built-in AI)PartialYesBuilt into Edge
Claude in ChromeFullNoChrome extension, desktop only
DiaFullNo (14-day trial)macOS, Windows waitlisted
FellouFullUnknownStandalone
GensparkFull (Autopilot)LimitedStandalone
Sigma AI BrowserFullYesStandalone
Samsung BrowserFullYesWindows, Android
Brave LeoNoYesExtension of Brave
Opera AINoYesExtension of Opera
Opera NeonFullYes (free as an agent target, ~$20/mo for its own AI)Standalone

Developer Tools & Frameworks

Browser automation for developers comes in three forms: open-source libraries like browser-use and Stagehand, MCP servers like Microsoft's Playwright MCP, and cloud browser infrastructure like Browserbase and Cloudflare Browser Run.

Open-Source Libraries

browser-use

The browser-use library has become the go-to open-source solution for AI-powered browser automation. It provides a Python and TypeScript SDK for building agents that can interact with websites using LLM-powered decision making.

The ecosystem includes stealth browser technology for bypassing anti-bot systems, session management for authenticated workflows, and both self-hosted and cloud deployment options. The library works with multiple LLM providers and has spawned a community of custom agents and integrations.

Stagehand (Browserbase)

Stagehand positions itself as "an OSS alternative to Playwright that's easier to use and lets AI reliably read and write on the web." Built by Browserbase, it combines the predictability of traditional automation with AI adaptability.

The key feature is natural language commands. Instead of writing selectors and click handlers, you describe what you want to happen. Stagehand's self-healing capabilities mean scripts continue working even when websites change their markup.

Stagehand v3 launched in February 2026 as a complete rewrite with an AI-native architecture. The new version talks directly to the browser via the Chrome DevTools Protocol, cutting out the traditional automation layer and running 44% faster. It also added multi-language support and became driver-agnostic, no longer tied to a single browser automation framework.

Skyvern

Skyvern focuses on enterprise automation use cases. It's a Y Combinator company building AI agents for tasks like form filling, data extraction, and workflow automation. The platform emphasizes reliability and accuracy for business-critical processes.

AgentQL and Notte

The space includes several other notable libraries. AgentQL provides a query language specifically designed for AI agents to extract structured data from web pages. Notte focuses on research agent workflows, helping developers build systems that can gather and synthesize information across multiple sources.

MCP Servers

The Model Context Protocol has become the standard for connecting AI models to external tools, including browser automation.

Microsoft Playwright MCP

Microsoft released the official Playwright MCP server in March 2025. This provides browser automation capabilities through the MCP standard, making it compatible with any AI system that supports the protocol.

The implementation uses accessibility snapshots rather than screenshots, which means it works with non-vision models and provides faster, more reliable automation. Published as @playwright/mcp on npm.

Community MCP Servers

The MCP ecosystem includes multiple community-built browser automation servers. These range from Puppeteer-based implementations to specialized servers for specific use cases like web scraping or form automation. The MCP server directory catalogs available options.

Cloud Browser Infrastructure

Running browser automation at scale requires infrastructure. Several companies provide cloud browsers specifically designed for AI agents.

Browserbase

The company behind Stagehand also provides cloud browser infrastructure. Browserbase offers headless browsers with anti-detection features, proxy rotation, and session management designed for AI agent workloads.

Browserless and Steel

Browserless provides headless Chrome as a service, focusing on reliability and scale for automation workloads. Steel Browser emphasizes stealth capabilities for workflows that need to avoid bot detection.

Hyperbrowser

Hyperbrowser offers managed browser infrastructure with a focus on AI agent use cases, including built-in LLM integration and natural language automation APIs.

Also worth keeping an eye on: Lightpanda, an open-source headless browser built from scratch in Zig specifically for AI agents and automation. Rather than wrapping Chromium, it's a purpose-built browser engine that claims 11x faster execution and 9x less memory than headless Chrome, while staying compatible with Puppeteer and Playwright through the Chrome DevTools Protocol. Still early, but the idea of a browser engine designed for machines rather than humans is interesting.

Cloudflare Browser Run

On April 15, 2026, Cloudflare's cloud browser service (renamed from Browser Rendering to Browser Run that day) added native WebMCP support. Lab sessions expose navigator.modelContextTesting.listTools() and executeTool(), letting developers test WebMCP-enabled websites against a real headless Chrome 146 environment. Concurrency limits jumped from 30 to 120 simultaneous browsers, and Session Recordings now capture every DOM change and navigation event for debugging. I covered why this matters for the rest of the model vendors in Cloudflare Added WebMCP to Browser Run: Every Model Vendor Will Follow.

Enterprise & API Solutions

API-first browser automation for enterprises comes from the major model vendors (Anthropic's Computer Use, Google's Project Mariner, OpenAI's Computer-Using Agent, and Amazon Nova Act) and specialized platforms like MultiOn, Airtop, and Manus.

Big Tech APIs

Anthropic Claude Computer Use

Anthropic's Computer Use API launched in October 2024 as the first major commercial offering in this space. Claude can control computer interfaces through screenshots and input commands, enabling automation of any desktop or web application.

The API is available through Anthropic's platform, Amazon Bedrock, and Google Cloud's Vertex AI. Computer Use remains in beta, with Anthropic advising developers to start with low-risk tasks.

Google Project Mariner

Project Mariner is Google's research prototype for browser automation. Currently available to Google AI Ultra subscribers in the US, with capabilities coming to the Gemini API for developers.

Mariner handles tasks like finding job listings, hiring service providers, and ordering groceries by interacting with websites autonomously. Google positions it as research into human-agent interaction rather than a finished product. As of March 2026, Mariner's web requests are identified by the new Google-Agent user agent, giving website owners visibility into agent-driven traffic in their server logs.

OpenAI Computer-Using Agent

OpenAI's Computer-Using Agent (CUA) powers both Operator and Atlas. It achieved 87% on the WebVoyager benchmark, one of the highest published scores for web automation tasks.

Microsoft Copilot Studio Computer Use

Microsoft announced Computer Use for Copilot Studio in April 2025. The feature allows Copilot Studio agents to interact with any application through its graphical interface, bridging the gap between AI assistants and legacy enterprise software.

The implementation runs on Microsoft-hosted infrastructure, keeping enterprise data within Microsoft Cloud boundaries. Target use cases include automated data entry, invoice processing, and market research.

Amazon Nova Act

Amazon launched Nova Act in March 2025 as an SDK for building browser agents. The model excels at web interaction tasks, achieving 0.939 on the ScreenSpot Web Text benchmark (compared to 0.900 for Claude and 0.883 for OpenAI CUA).

Nova Act integrates with Playwright for browser control and supports Python workflows with API calls and direct browser manipulation.

Specialized Platforms

MultiOn

MultiOn provides an API for web automation with a focus on reliability and scale. Their agents can handle complex multi-step workflows across websites, with built-in handling for authentication, CAPTCHAs, and dynamic content.

Airtop

Airtop offers browser automation infrastructure with AI integration, targeting enterprise use cases that require high reliability and compliance controls.

Manus Browser Operator

Manus Browser Operator takes a different approach. Rather than running in the cloud, it operates as a browser extension that controls your local browser. This gives it access to your authenticated sessions and trusted IP address, avoiding login prompts and CAPTCHA interruptions.

The extension launched in November 2025 for Chrome and Edge, with full user control over when and how automation runs.

The Foundation: Model Context Protocol

The Model Context Protocol (MCP) is the open standard that lets any AI system control a browser through one consistent interface.

Anthropic released MCP in November 2024 as an open standard for connecting AI models to external data sources and tools. Think of it as a universal adapter that lets any AI system talk to any tool or service through a consistent interface.

For browser automation specifically, MCP provides a standardized way for AI models to control browsers without each integration being custom-built. Microsoft's Playwright MCP is the canonical example: any MCP-compatible AI assistant can use it for browser automation.

The protocol has gained significant adoption. ChatGPT, Claude, Gemini, Cursor, VS Code, and GitHub Copilot all support MCP. The SDK sees over 97 million monthly downloads as of late 2025.

In December 2025, Anthropic donated MCP to the Linux Foundation, signaling its transition from a company project to an industry standard. This makes it a safe bet for developers building browser automation, as the protocol won't be subject to single-company control.

A major development came in February 2026, when Google released an early preview of WebMCP in Chrome Canary. WebMCP is a protocol for structured AI agent interactions with websites, introducing two new APIs: a Declarative API for HTML forms and standard page elements, and an Imperative API for dynamic JavaScript-driven interactions. Google is developing WebMCP with Microsoft through the W3C, aiming for an open standard that all browsers can adopt. I covered this in detail in What is WebMCP?.

In June 2026, WebMCP graduated from a Canary flag to an origin trial in Chrome 149, running through Chrome 156. Any website can register a trial token and expose tools to browser agents on production traffic.

The client side arrived in August 2026, and it is the most consequential change in this guide since the last update. Microsoft opened its own WebMCP origin trial in Edge 150, running to November 17, so a second browser engine now supports it. More importantly, OpenAI added WebMCP support to ChatGPT, covering the browser built into the desktop app, ChatGPT Work and Codex, with the available tools visible to users under "Site tools" in the address bar. An OpenAI engineer upstreamed that status to the W3C repository on August 26.

Until then the honest summary was that early adopters were building a socket with nothing to plug into it. That is no longer true. A mainstream agent product now calls site tools in production. The implementation tracker currently shows origin trials live in Chrome and Edge, support in ChatGPT Desktop, experimental support in Brave's Leo, and standards-position issues only for Firefox and Safari.

Two limits worth knowing before you build. ChatGPT supports only JavaScript-registered tools on the top-level page, not the declarative HTML form attributes and not tools inside iframes. And Chrome's own documentation says the API "is primarily designed for local browser workflows with a human in the loop," which is a different target from server-side crawling.

Notable Absences

The list of holdouts is shrinking. Vivaldi still refuses agentic features outright, while Firefox and Safari both released their first AI capabilities in 2026, each with heavy guardrails.

Vivaldi maintains an explicitly anti-AI stance, focusing on user privacy and customization over AI features. Their CEO has been vocal about concerns with AI data practices.

Firefox delivered the guardrails before the features. The promised "AI Kill Switch" arrived in Firefox 148 on February 24, 2026, a master toggle that disables every AI feature, current and future. Then it arrived. The mode Mozilla had been developing in the open as AI Window launched on August 18, 2026 under a new name, Smart Window, in beta and no longer behind a waitlist. Firefox 155 opened it to all users in the USA, Canada and France on September 1. It brings web-aware AI chat with real-time source links, natural-language history search, automatic tab grouping and duplicate-tab closing. The February kill switch still turns all of it off, and an enterprise policy can disable generative AI centrally. The University of Washington's July 2026 security study rated Firefox's AI mode the safest of the seven agentic browsers tested, and also the most limited in what it can do, which is the same trade Mozilla is still making.

Safari got its first agentic feature at WWDC 2026 in June. The Passwords app now uses Apple Intelligence and Safari to visit websites and change insecure passwords on the user's behalf, and the revamped Siri, built with Google's Gemini family of models alongside Apple's own, gained visual intelligence and cross-app context awareness. Agentic password repair is a narrow, high-trust task rather than open-ended browsing, which fits Apple's privacy-first positioning: let the agent act only where the failure mode is contained.

What This Means for Your Website

Every website now serves two audiences: human visitors and the AI agents browsing on their behalf.

These agents aren't just demos or developer tools anymore. Chrome auto browse alone means billions of potential agent visits, now including Android phones at the OS level. Add Comet, the ChatGPT desktop app and Chrome extension inheriting Atlas's agentic browsing, and all the developer tools building on this infrastructure, and agent traffic is becoming a meaningful percentage of web interactions.

The websites that work well with these agents will get included in agentic workflows. The websites that don't will see agents fail, give up, and go to competitors.

What Helps Agent Browsing

  • Semantic HTML: Use proper elements. Buttons should be <button>, not <div onclick>.
  • Clear labels: Form inputs need labels. Buttons need descriptive text.
  • Logical structure: Navigation that makes sense. Headings that establish hierarchy.
  • Accessible design: Websites that work with screen readers generally work with AI agents.
  • Server-rendered content: Critical information should be in the HTML, not loaded by JavaScript.

What Breaks Agent Browsing

  • Aggressive anti-bot measures: CAPTCHAs on every interaction. IP blocking.
  • Mouse-only interactions: Hover states, drag-and-drop without keyboard alternatives.
  • Infinite scroll without pagination: Agents need to know when they've reached the end.
  • Content behind unlabeled buttons: "Show more" that doesn't indicate what it shows.
  • Heavy client-side rendering: Blank pages until JavaScript executes.

Practical Steps

  1. Test with a screen reader. If VoiceOver or NVDA can navigate your website, agents probably can too. The text-only Lynx browser is another useful check for how agents might parse your content.
  2. Check your source HTML. View source on critical pages. Is the important information there?
  3. Add llms.txt. A simple markdown file that helps AI agents understand your website's purpose.
  4. Review your bot policies. Make sure you're not blocking legitimate AI crawlers.
  5. Run Glimpse. Glimpse by Web Performance Tools shows you how AI agents see your page.
  6. Score your agent readiness. Cloudflare's isitagentready.com scans any website against emerging agent-legibility standards. Read the per-check list rather than fixating on the composite score, which can be structurally misleading.

I cover these topics in depth in What is Agent Experience Optimization.

The Ninth Circuit Ruled That The User, Not The Agent's Vendor, Accesses Your Website

On August 4, 2026 the Ninth Circuit vacated the injunction that had blocked Perplexity's Comet from Amazon, the first federal appellate decision on whether an AI agent acting for a logged-in user is an authorized visitor. Getting there took ten months. The Amazon vs Perplexity lawsuit, filed in November 2025, reached its first milestone on March 10, 2026, when Senior U.S. District Judge Maxine Chesney granted Amazon a preliminary injunction blocking Comet from accessing password-protected Amazon accounts. The judge found Amazon is likely to succeed on its claims that Perplexity violated the federal Computer Fraud and Abuse Act, drawing a crucial distinction: Comet accesses Amazon accounts "with the Amazon user's permission, but without authorization by Amazon." The order also requires Perplexity to destroy any Amazon data collected through Comet.

Perplexity appealed the next day, and the Ninth Circuit Court of Appeals stayed the ruling, so Comet kept operating throughout.

Perplexity appealed, arguing the Computer Fraud and Abuse Act does not apply to an AI assistant that runs locally on a user's device, accesses only the user's own account data, and never connects directly to Amazon's servers. The filing framed Comet as analogous to Safari: the user's tool, not Perplexity's. The Ninth Circuit heard oral arguments in Seattle on June 11, 2026.

The panel ruled, and Perplexity won. In Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, published and therefore precedential, Judge Milan D. Smith Jr. wrote for a panel that vacated the preliminary injunction and remanded. The holding is one sentence: "It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com." The Assistant, the court said, "is a tool, not a person for statutory purposes," and the statute punishes whoever "intentionally accesses" a protected computer.

Read the reasoning before you read the headline, because three things narrow it considerably.

First, the court said what it was not doing. "Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI." It expressly left open tort claims and a different record.

Second, the holding rests on where Comet runs. The court quoted the Electronic Frontier Foundation and Mozilla amicus brief approvingly: "Perplexity's servers never directly access Amazon's servers." An agent that runs on the vendor's own infrastructure is a different case, and the panel said so, reserving whether Perplexity might "exercise control over the Assistant in such a way as to gain entry to Amazon's servers."

Third, and most useful to a website owner, the court pointed the fight somewhere else. Its footnote preserves the alternative: "This outcome does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users." So the anti-hacking statute is largely off the table, and your terms of service are now the instrument. What you can stop an agent doing is whatever your terms actually say you can stop it doing, and no more.

The case is not over. Amazon has petitioned for rehearing en banc, supported by an amicus from the Software and Information Industry Association, and the case returns to the district court on remand. I broke it down in full in Amazon v. Perplexity: The CFAA Case That Decides Whether AI Agents Can Visit Your Website.

The scraping side of the law moved in July, and then moved again. On July 20, 2026, Chief Judge Yvonne Gonzalez Rogers dismissed Google's DMCA anti-circumvention claims against SerpApi, ruling that an anti-bot wall protecting ad revenue is not copyright protection. That did not end it: Google filed a narrowed amended complaint in August, focused on licensed material rather than the Shopping and Maps claims, and SerpApi moved to dismiss a second time on August 25. The theory is alive, only smaller. I wrote about the first ruling in Google Built Its Library By Scraping The Web, So It's Fair Game Too.

Regulation moved too. The EU AI Act's Article 50 transparency obligations became applicable on August 2, 2026, requiring providers to design systems so that people are "explicitly informed whenever they interact with an AI system directly." For anyone operating a browser agent in the EU, that is the first binding duty to say out loud that the visitor is a machine.

The implications run well beyond Amazon. Every retailer, marketplace and booking website with a login now knows that the anti-hacking statute will not do this work for them, and that whatever they want to say about agents acting for their own customers has to be said in their terms. I wrote about what that means for sellers in Selling to AI: The Complete Guide to Agentic Commerce.

Agentic Browser Security

The security surface of agentic browsers is expanding faster than defences. In March 2026, Zenity Labs disclosed "PleaseFix", a family of critical vulnerabilities affecting agentic browsers including Perplexity Comet, allowing attackers to hijack AI agents, access local files, and steal credentials within authenticated sessions. Separately, researchers demonstrated tricking Comet into completing a phishing attack in under four minutes.

These aren't theoretical risks. When an AI agent browses with your credentials and gets manipulated by malicious content on a third-party page, the damage lands on your account. Palo Alto Networks responded to this threat by unveiling Prisma Browser, positioned as the industry's most secure browser built for the agentic AI era, with protections against shadow AI agents, prompt injection attacks, and agent hijacking. The emergence of a security-focused agentic browser from an enterprise security vendor signals that the industry recognises this as a real and growing attack surface.

Four separate agentic-browser attacks were disclosed in August 2026, and the pattern across them is that the same class of attack now works against every major vendor. On August 3, Zenity Labs expanded PleaseFix from Comet alone to five named agents: Claude in Chrome, Gemini in Chrome, Comet, Atlas and Copilot in Edge, adding two techniques it calls Intent Collision and HistoryFixing. Two days later it published Grand Theft Atlas, a zero-click hijack of ChatGPT Atlas triggered by a single planted comment on a public thread and carrying across authenticated sessions. OpenAI acknowledged it in February and had not patched it at publication. The product was switched off four days later.

The same day, Zenity showed an indirect prompt injection against Claude in Chrome escalating to full account takeover by coercing the extension's own JavaScript tool into running arbitrary code on any domain. Anthropic closed both reports as ineligible for its vulnerability disclosure programme. That is the part worth sitting with: a working account-takeover chain, declared out of scope.

The one CVE of the period went the other way. On August 18, Varonis disclosed CoSnitch, CVE-2026-24301, an undocumented URL parameter in Microsoft Copilot that auto-executed an attacker's prompt on a single click, exfiltrated from connected accounts, and planted memory rules that survived a password reset. Microsoft patched it on the disclosure date. The entire attack surface was a link.

The academic picture is no more reassuring. A University of Washington study published July 3, 2026 tested seven agentic browsers, including ChatGPT Atlas, Chrome with Gemini, Claude in Chrome, and Perplexity Comet, and found that four of them let attackers bypass the same-origin policy, the 1995-era boundary that stops one website from reading another's data. The researchers demonstrated a proof-of-concept attack on Atlas in which embedded malicious content stole sensitive information from other websites. Atlas was switched off five weeks later, which is one way to close a finding. Their conclusion was blunt: browser agents aren't ready for the public. The safest browser in the study, Firefox's AI mode, was also the least capable, which is the tradeoff every vendor in this space is currently making somewhere on the dial.

What Comes Next

MCP is the unifying standard for agentic browsers, and the major platforms have converged on similar autonomous-browsing capabilities. The consolidation predicted in earlier versions of this guide has happened. OpenAI killed its standalone browser, Microsoft folded Copilot Mode back into Edge, and Google baked its agent into Android at the OS level. The pattern across all three: agents are disappearing into the surfaces people already use, the operating system, the existing browser, the chat app, rather than pulling users into new standalone products.

Two things cut against that in August, and they are worth watching. Anthropic released a browser inside Claude Cowork, which is a model vendor building a browser rather than a browser vendor building a model. And Opera made Neon free to use as an agent target, which is a browser positioning itself as infrastructure for somebody else's agent. Both point the same direction: the browser stops being the thing a person uses and becomes the thing an agent drives.

August also settled two questions this guide has carried for months. WebMCP got a real client, so the tools websites expose now have something to call them. And the Ninth Circuit took the anti-hacking statute away from website owners and pointed them at their terms of service. Both fell in the same month that four separate attacks showed the major browser agents can be hijacked by content they merely read. The legal permission to visit expanded exactly as the technical case for trusting the visitor got weaker.

The distinction between "browser" and "AI assistant" is blurring. When Chrome can complete tasks autonomously, when ChatGPT can browse the web on your behalf from a desktop app, the traditional concept of a browser as a passive viewing tool feels outdated.

Two things changed in August that give you something to do rather than something to watch.

Open your terms of service and read the section on automated access. Until August it barely mattered, because a website could point at the Computer Fraud and Abuse Act. After the Ninth Circuit, that statute does not reach an agent acting for your own logged-in customer, and the court said so while pointing at your terms as the thing that does. If your terms are silent on agents acting for users, your position on agents acting for users is silent too.

Then decide whether you want to expose tools. WebMCP has a real client now, so registering a tool is no longer building a socket with nothing to plug into it. Start with a read-only tool on one page, run it against ChatGPT's desktop browser, and see whether the agent uses it or ignores it. That answer takes an afternoon and it is yours rather than a vendor's.

Your next million visitors won't be human. The two decisions above are the ones that determine what they find.

QUESTIONS ANSWERED

What is an agentic browser?

An agentic browser is a web browser enhanced with AI capabilities that allow it to autonomously browse, interact with, and perform actions on websites. Instead of just displaying pages, these browsers can scroll, click, fill forms, and complete multi-step tasks on your behalf.

Are AI agents already visiting my website?

Yes. Between Perplexity Comet, Claude in Chrome, Edge's built-in AI, and dozens of developer tools, agentic traffic is already a meaningful percentage of web interactions. Chrome auto browse started as a US desktop feature and went live on Android at the operating-system level in late June 2026. Gemini in Chrome reached all US Android users on August 18, 2026, though auto browse itself remains US-only and limited to Google AI Pro and Ultra subscribers. These agents browse, click, fill forms, and complete transactions on behalf of real users.

What breaks agentic browser navigation?

Common problems include aggressive CAPTCHAs, forms that require mouse hover states, infinite scroll without pagination, content hidden behind unlabeled buttons, and heavy client-side JavaScript rendering. If a screen reader struggles with your website, AI agents will too.

What's the difference between AI crawlers and agentic browsers?

AI crawlers (like GPTBot or ClaudeBot) index content for training or retrieval. Agentic browsers actively perform tasks: clicking buttons, filling forms, comparing prices, completing purchases. Crawlers read your website, while agents use it on behalf of humans.

Which AI browsers are free?

Perplexity Comet is completely free with agentic features. Microsoft Edge's built-in AI features are free after the Copilot Mode retirement in May 2026. Chrome's Gemini features have a free tier but full auto browse requires Google AI Pro or Ultra. Opera Neon added a free plan in August 2026 that lets other agents drive it, though its own AI stays paid. Brave Leo and Opera AI offer free AI chat assistants but no agentic capabilities.

What happened to ChatGPT Atlas?

OpenAI announced on July 9, 2026 that it was retiring the standalone ChatGPT Atlas browser, and it stopped working on August 9, 2026, 292 days after its October 2025 launch. Bookmarks, tabs and history did not migrate. The agentic browsing features moved into the ChatGPT desktop app, the ChatGPT Chrome extension and Codex rather than disappearing.

How do I optimize my website for AI browsers?

Focus on semantic HTML, clear button labels, proper form markup, and accessibility standards. Avoid patterns that break automation: infinite scroll without pagination, forms requiring hover states, and content hidden behind unlabeled buttons. Websites that work well with screen readers typically work well with AI agents.