If a human can see it, so can an AI agent

Where agentic browsing actually stands this month, why the biggest organisations have the most to gain and the least permission to act, and what happens to any revenue line built on friction.

Friends,

your weekly AI briefing is here - designed to help you respond to AI, not react to the noise. No curveballs. No chaos. Just clarity.

📰 The State of Agentic Browsing - August 2026

This one is different. Not the week that was, but where this whole field actually stands right now - because agentic browsers went from party trick to quiet infrastructure while most of us were looking elsewhere, and the decisions they force are landing this month.

An agentic browser doesn't just show you the web - it uses it for you. Logs in, clicks, fills forms, buys things, while you watch.

Two questions arrived with them, and neither is settled: are they good enough to trust, and are they even allowed through the door. Permission is being answered twice over - once in a US appeals court, once in website settings, with a deadline of 15 September. Trust we come to at the end.

Here is the field as it stands.

Browser

Reach (Aug 2026)

Capability

Suitability

Appropriateness - the question that decides it

Perplexity Comet

~18m monthly users - third-party estimate, ±15%. Perplexity publishes nothing

Full agentic. Logs in, fills forms, completes purchases. Mac, Windows, Android, iPhone

Short supervised tasks. The one named in the Amazon case

Will you let a third-party agent inside logged-in sessions holding company or customer data?

ChatGPT Atlas

Never disclosed. macOS only for its entire ten months

Full agentic but slow - reportedly ten minutes to put three items in a cart

Retiring 9 August into ChatGPT Work and a Chrome extension

No longer a question. Plan the migration, not the adoption

Microsoft Edge, Copilot Mode

Rides Edge's existing enterprise install base

Agentic actions, restricted to sites IT has approved

Business preview since May 2026, under IT policy control

Already governable. Your question is which sites you scope, not whether to allow it

Brave Leo

100m+ use the browser - first-party. Brave doesn't say how many use Leo

Lighter agentic depth, privacy-first by design

Assistive rather than autonomous

The lowest-exposure option if privacy is your binding constraint

Dia (The Browser Company, now Atlassian)

Never disclosed. macOS only, Windows waitlisted

Agentic, aimed squarely at enterprise knowledge work

Early, and being rebuilt as an enterprise browser post-acquisition

Is your bet on the browser, or on the Atlassian stack it now serves?

Google Chrome

The default for most of the web

Not agentic itself - but ships a new standard that lets a website tell visiting agents what they are allowed to do

The permission layer, not the agent

Do you control what your own sites declare to visiting agents?

Read that last column carefully, because it is the one most evaluations skip. Notice too what the reach column cannot tell you: almost nobody in this field publishes usage numbers. The money has still moved - Perplexity raised $200m specifically for Comet, pitched as the front door to the agent economy, and Atlassian paid $610m for The Browser Company. This field is being valued on strategic position, not on disclosed users.

The consolidation was faster than most people noticed. ChatGPT Atlas launched in October 2025 and will not reach its first birthday - OpenAI is retiring it on 9 August, folding the capability into a desktop app called ChatGPT Work and a Chrome extension. It never shipped beyond macOS. Perplexity's Comet took the opposite path: free since October 2025, on every major platform, and it kept climbing while Atlas folded. Meanwhile the two names already open on most desktops built the same capability into tools you have anyway - Microsoft put agentic actions into Copilot Mode in Edge, and Chrome now lets a website tell an agent exactly what it is allowed to do, through navigator.modelContext.

The traffic numbers are the story. HUMAN Security, which tracks activity across a huge slice of the web, found traffic from AI agents grew 7,851% year on year - roughly 80 times more - and by spring, agentic browsers already made up around 71% of that AI traffic. Automated traffic is now growing faster than human traffic, for the first time HUMAN has measured.

A court is deciding whether your agent is allowed in. Amazon sued Perplexity under the US Computer Fraud and Abuse Act, arguing Comet was shopping inside customers' logged-in accounts without Amazon's permission. A federal judge granted a preliminary injunction on 10 March; a US appeals court paused it a week later, heard arguments on 11 June, and has not ruled. It is American law, but it is the first serious answer anywhere to whether a website can bar somebody else's agent - and everyone will be reading the ruling. Note who is arguing what: Amazon is not debating whether its own staff may use agentic browsers. It is trying to stop somebody else's agent, acting for its own customers. Hold that thought.

And there is a dated deadline, six weeks out. From 15 September, Cloudflare will default-block any "mixed-use" crawler - a bot that both trains AI models and fetches live pages to answer questions - on any page carrying advertising, unless the site owner turns that off deliberately. Don't know whether you are on Cloudflare? Most people don't. Ask whoever runs your website. Cloudflare is also evolving Pay Per Crawl into something closer to pay-per-use, so a publisher can charge for the value an agent's visit generates downstream.

Let's get into it.

🔥 Urgent Priorities

✅ No fires to fight here - nothing below needs a same-day response

✅ Agentic browser extensions are already showing up inside plenty of businesses whether anyone signed off or not, the same pattern every new tool wave brings, and worth a five-minute look at what is actually installed

✅ If your website carries any ad revenue, Cloudflare's 15 September default-block is worth a calendar entry now, while there is still time to set the crawler rules you actually want

✅ If you sell access to data - an API, a subscription, a licensed feed - read the Strategic Insight before your next pricing review

No panic needed. What it calls for is that quick check on what is already running, and a decision on the Cloudflare settings before the deadline picks one for you.

🎯 Strategic Insight

Tension: size decides both how much you stand to gain and how little you are allowed to do about it - and it pulls the two in opposite directions.

The larger the organisation, the less acceptable an agentic browser is to use. Governance, compliance, data protection, procurement, audit, brand risk - every one of those functions says no, and every one of them is right to.

The larger the organisation, the more valuable the data sitting behind a human-viewable screen that an agentic browser can now reach.

So the businesses with the most to gain have the least permission to act, and the businesses with the most permission have the least to gain. Draw it and the two lines cross:

              PERMISSION TO USE      VALUE ON OFFER
Startup       ████████               ██
Mid-market    ████                   ████
Enterprise    ██                     ████████

That is the scissors, and three things fall out of it.

First, the opportunity is asymmetric - and it favours the small. Startups have the risk appetite and, increasingly, the capability to manage the risk properly. They have no legacy governance apparatus to satisfy and no board to reassure. They will move on this while larger competitors are still forming a working group. That gap compounds.

Second, large organisations are watching the wrong door. Almost every enterprise conversation about agentic browsers is an internal-use policy question: should our people be allowed these tools? The larger exposure runs the other way - your customers, partners, suppliers and competitors pointing agentic browsers at you. You get no vote on that one. It is happening already. Amazon v Perplexity is precisely this argument, which is why it is worth watching whichever side of it you sit on.

Third, and this is the one with a number attached - agent traffic up roughly 80 times in a year: if a human can see it, an agent can see it. Every business monetising access to data rather than the data itself has been selling friction - paid APIs, licensed feeds, per-seat research platforms, price-gated catalogues, legacy portals charging for a login. Agentic browsing dissolves the friction and leaves the data. If your revenue line depends on it being tedious to get at something a human is already permitted to see, that line has a hole in it, and the hole gets bigger every quarter.

Optimistic insight: the same fact is a commercial opening, and a large one. Somebody has to work out what an agent's visit is worth and how to charge for it - and that pricing model does not exist yet. Cloudflare is building the first serious attempt: Pay Per Crawl becoming pay-per-use, charging not for the fetch but for the value the visit generates downstream. That is the opening move in pricing for machine customers, and it will not be the last. This is a genuinely new commercial front, being defined this year by whoever turns up.

The decision tool still holds - capability, suitability, appropriateness, asked in that order, per task rather than per product. What this edition adds is that appropriateness is not a property of the tool. It is a function of your organisational context. The same task, with the same browser, is appropriate in a twelve-person startup and inappropriate in a twelve-thousand-person bank - and both readings are correct. "Are agentic browsers safe?" has no general answer. It only has yours.

If you are...

Your real exposure

Your first move

Startup or small team

Low internal risk, high upside, few gatekeepers

Use them. Take the advantage while larger competitors cannot move

Mid-market

Both directions at once, and usually nobody owning either

Name an owner. Decide internal-use policy and external exposure as two separate questions

Enterprise

Governance blocks internal use, while customers, partners and competitors point agents at you regardless

Start with the external exposure - it is live now and you never consented to it. Then take an IT-scoped posture for internal value without startup-level risk

What's shifting: that middle path already exists in production. Copilot Mode in Edge went to business preview in May 2026 with agentic browsing that IT scopes site by site, under data protection policy. It is the proof that a large organisation does not have to choose between all and nothing.

Why this matters now: only 16% of people trust AI answer engines "a great deal", and 81% are wary of AI reaching their personal data - yet 48% say they are comfortable with agentic features once a human is visibly still watching. Oversight is what moves that number. And caution carries its own risk: the two governance problems that show up most often in practice are under-adoption and cybersecurity, so sitting this out is not automatically the safer choice. AI's power is real enough to be worth engaging with, the way fire is - and the risks that come with that power are exactly what is worth designing for.

Action - two tracks, and you need both.

Defence: work out what an agent can already see of your business, because that is now a commercial fact about you, not a hypothetical. Then ask the harder question of any revenue line that charges for access: what happens to this when the friction goes? Route the governance questions to whoever already owns them - risk taxonomy with risk management, cyber with cyber, vendor questions in procurement, data questions with whoever holds data protection.

Offence: put agentic browsing on the roadmap using Three Horizons - respond to what is urgent now, prepare for what is coming next, consider what could still surprise you - and say plainly which one it sits in for you today. For most larger organisations that is consider, with two or three named triggers that would move it to respond: the court ruling landing either way, a vendor you already pay folding the feature into a daily tool, or a competitor visibly getting real value. For a startup, it is respond, and it is already late.

🤓 Geek Out

1️⃣ Why an agent that aces the demo can still fail by Tuesday

Here is the trust question, answered. Every agentic browser looks close to magic in a five-minute demo, because five minutes is exactly where they are strongest. The trouble shows up over longer, multi-step runs: researchers tracking how these tools actually perform found that a small error rate on each individual step compounds fast - chain twenty steps together and a 2% error on each one adds up to roughly a third of all runs failing outright. The same research puts today's best agents as reliable for a few hours of continuous work, and closer to a coin flip once a task stretches much further than that.

Why it matters: If you are evaluating one of these tools, a slick demo of a five-minute task tells you nothing about whether it survives a ninety-minute one - ask to see it run something closer to the length of your real job. If your own team is building agent tooling, design for short, supervised hops with someone checking in between steps.

👉 Action: Before you trust an agent with anything that takes longer than about half an hour, break the job into checkpoints you approve one at a time.

2️⃣ Two browsers being built for machines, not people

Almost everything an AI agent uses to browse the web today is either a full copy of Chrome or an automation script bolted onto one, carrying decades of features built for a person looking at pixels. Two projects skip that entirely. Lightpanda is a headless browser built from scratch for AI agents: in published tests, it used about 16 times less memory than Chrome and finished the same job roughly 9 times faster. It is open-source, free for anyone to inspect or build on, openly still in beta, and has grown past 33,000 stars on GitHub - a rough popularity gauge among developers - since this newsletter first flagged it as a cost story. Vercel Labs took a different route with agent-browser, a fast command-line tool that talks to a real Chrome under the hood but hands an agent a clean, structured read of a page instead of a screenshot to squint at - it is pushing 40,000 stars of its own. Neither is a stripped-down version of an ordinary browser. Both were designed from the ground up with a machine as the reader.

Why it matters: Geek Out 1 explained why longer agent runs break: too much guessing, page by page, with small errors compounding at every step. This is the direct fix - a browser engineered to hand an agent a small, structured view of what is actually on the page removes exactly that noise. If your team is building or buying agent tooling, the browser doing the looking matters as much as the model doing the deciding.

👉 Action: If a supplier has ever told you a piece of public information was too hard to automate, it is worth asking again in six months.

3️⃣ The security hole nobody can fully close, and what to do about it anyway

Hostile instructions hidden inside an ordinary web page, email or calendar invite can hijack an agent mid-task, because the model reads instructions from whatever it is looking at the same way it reads instructions from you. Researchers have found working versions of this attack - known as prompt injection - in both Atlas and Comet, and OpenAI has said plainly that it is unlikely to ever be fully solved, in much the same way phishing never quite goes away.

Why it matters: If you use one of these tools personally, treat anything an agent reads on your behalf the way you would treat a public forum post. If you hold governance for a team, this is a working example of a rule worth adopting everywhere: judge a tool by what it can reach, set against what it is actually allowed to touch.

👉 Action: Audit which accounts and data sources any agentic browser in your business can currently reach, and switch off the ones it does not need.

🎨 Weekend Playground

Comet, Perplexity's browser, is free with no subscription needed, on Mac, Windows, Android and iPhone.

Why this matters: This is the external-exposure question from the Strategic Insight, made hands-on in an hour. Most people who try an agentic browser point it at someone else's website. Pointing it at your own is the more useful hour: you find out exactly what an agent - and by extension any prospect, partner or competitor using one - can already see about your business.

👉 Mission:

  • On Android, install Comet from the Play Store; on iPhone, from the App Store - same app either way. On a laptop, the desktop version installs just as easily

  • Sign in, then ask it to research your own company, find your public pricing, and summarise what a prospect would conclude before buying anything

  • Ask it to go one step further - start a booking, an enquiry form, or a signup - and watch exactly where it gets stuck or needs you to step in

  • Note what it could reach that you assumed was effectively private, and what it could not. The first list is your exposure. The second is whatever friction you are currently charging for

📢 Share the Optimism

If The AI Optimist helps you think more clearly, forward it to someone else handling the shift.

And here is the question I am curious about right now: what can an agent already see about your business today - and is any of it something you currently charge for? Reply and tell me. I read every message and I will come back to you personally.

Stay strategic, stay generous.

Hugo & Ben