Blog AI and Agents · Beyond the Four Walls · Part 8

The browser is becoming the assistant. Your booking form is its next test.

Google, Microsoft, Anthropic, Perplexity and Opera have all put an agent inside the browser that can click, type and fill in forms. OpenAI built one and shut it down. Part 8 of Beyond the Four Walls: what that means for the form on your website.

A studio front desk with a booking form on a screen, and a small paper robot hand holding a pen to fill in the form while a customer relaxes in the waiting area

For most of the last two years, when people talked about AI agents using the web, they meant something that happened somewhere else: a bot on a server reading your pages. That picture is now out of date. The agent has moved into the browser itself, the same Chrome or Edge window your customer already has open, signed in to their own accounts.

That changes who is filling in your booking form. Usually it is still a person. But it can now be software, working inside a real browser on that person's behalf, clicking your buttons and typing into your fields. It does not look like a bot. It looks like a customer, because technically it is using the customer's browser.

In Part 7 we looked at Google booking appointments from search. This part is about the other route in: the browser that does the work for you.

Who built an agent browser, and what happened to it

In the past fifteen months nearly every company that makes a browser, or wants to, has shipped one. Not all of them survived. Here is where things stand in October 2026, from each company's own announcements.

Browser or featureMakerLaunchedAgent can click and fill formsAvailability, October 2026
CometPerplexityJuly 9, 2025YesFree to download worldwide since October 2, 2025
Copilot Mode in EdgeMicrosoftJuly 28, 2025Yes, now as Browse with CopilotCopilot Mode retired May 13, 2026. Browse with Copilot is for US Microsoft 365 Premium subscribers, with usage limits
Opera NeonOperaSeptember 30, 2025 (first users)YesPaid subscription, $20 a month in the US
ChatGPT AtlasOpenAIOctober 2025Yes, in agent modeShut down August 9, 2026. Agent browsing moved into the ChatGPT desktop app and a Chrome extension
Gemini in Chrome, auto browseGoogleJanuary 28, 2026YesPreview for US Google AI Pro and Ultra subscribers on desktop, and on Android in the US since August 18, 2026
Claude in ChromeAnthropicGenerally available August 26, 2026YesEvery paid Claude plan, Chrome on desktop only
DiaThe Browser Company, owned by Atlassian since October 21, 2025Not confirmedNot stated on its siteFree download for macOS and Windows

Two things stand out. The first is that the standalone AI browser is not winning on its own. OpenAI said in July it was deprecating Atlas and "moving browser-based agentic capabilities into ChatGPT and Codex," and TechCrunch's read was that OpenAI "appears to have concluded that the browser is a feature, not the destination." Microsoft folded Copilot Mode back into ordinary Edge in May.

The second is that the feature itself is spreading, not shrinking. Google put auto browse into Chrome, the browser most of your customers already use. Anthropic made Claude in Chrome available to every paid plan. The agent did not need its own browser. It moved into the one people had.

What these agents actually do on a page

The descriptions are strikingly similar. Google says auto browse can scroll, click and enter text, fill out forms, and handle chores like scheduling appointments, with a daily cap on how many actions you get. Anthropic says Claude in Chrome can read the page, type, click links, move between pages and fill out forms using the person's existing logins. Opera says Neon can check several sites, compare information and fill out forms inside the user's own signed-in session.

That last detail matters for a gym or a spa. These agents work inside the customer's browser, with the customer's cookies and saved details. To your website, the visit looks like any other visit from that person's laptop. Your analytics will not label it. Your booking system will not know.

A reception desk at a day spa where a translucent cursor hand reaches out of a laptop screen to tap a booking button, while the customer sits on a sofa in the background reading a magazine
The visitor on your booking page may be a cursor working for someone on a sofa.

The makers that describe their safeguards all built in a pause. Google says auto browse is "designed to pause and explicitly ask for your confirmation" before a purchase or a social post, and 9to5Google reports that you press the final buy button yourself. Chrome's security team says the same about payments. So the realistic picture for a class booking or a facial is this: the agent finds you, picks the time, fills in the name, email and phone, and then hands the last click to the person. If any step before that breaks, the person never gets to the last click with you. They get there with someone else.

The referral numbers behind it

How much traffic comes this way? Nobody publishes a clean count of agent-driven browser visits yet. What we can measure is referral traffic from AI assistants, and it is moving fast.

101%Growth in ChatGPT referral traffic, January to August 2026
95.1%ChatGPT's share of AI assistant referrals in August
2.4%Gemini's share in August

Source: BrightEdge, September 24, 2026

ChatGPT dominates referrals, and it no longer has its own browser. That is a useful reminder that these numbers measure the assistant, not the browser it runs in. They also measure clicks that leave the assistant and land on your site, which is not the same as an agent filling in your form. Treat them as a sign of direction, not a count of bookings.

The security warning the makers wrote themselves

The companies building these agents have been unusually blunt about the main risk. It is called prompt injection: text on a web page that tries to give the agent orders, like a note slipped into a stack of paperwork.

Prompt injection, much like scams and social engineering on the web, is unlikely to ever be fully "solved."
OpenAI, December 2025

That line comes from OpenAI's post on hardening Atlas, as reported by TechCrunch, which also quoted OpenAI conceding that agent mode "expands the security threat surface." Google's Chrome team wrote that "the primary new threat facing all agentic browsers is indirect prompt injection," and named where it can hide: malicious sites, embedded content, and "user-generated content like user reviews." Brave's researchers showed in August 2025 how a hidden Reddit comment could steer Perplexity's Comet into pulling a one-time password out of the user's Gmail.

Anthropic published the most detailed numbers. In its testing against professionally red-teamed attacks, the share of attacks that succeeded fell sharply between model generations and with added safeguards.

Share of red-team prompt injection attacks that succeeded in Anthropic's browser tests
Older model, no extra safeguards17.6%Older model, with probes16.7%Newer model, no extra safeguards3.8%Newer models, probes and classifier0%

Source: Anthropic, August 26, 2026. Older model is Claude Opus 4.5 (safeguards as of November 2025); newer is Opus 5. One current model, Fable 5, still showed 0.3% with safeguards.

Read that chart both ways. The progress is real. The risk is not zero, and every maker says so. Their answer is the same everywhere: the agent pauses before money moves, and a person confirms.

For a local business this has two practical edges. First, your reviews, comments and any text you let the public post on your site are now content an agent reads. Moderate them like they matter. Second, never try to talk to agents with hidden text. A line of white-on-white instructions aimed at AI looks exactly like the attacks these companies are training their agents to detect and ignore.

Can an agent book a class on your site?

Here is the test that matters. You do not need any of these products to run it, but if you have a paid Claude plan or Google AI Pro, try it with a real agent. Otherwise, walk through it yourself as if you could only read the labels.

  1. Find the button by its words

    Every button that starts a booking should say what it does in real text: "Book a class," "Book a facial." An icon with no label, or a button that is really an image, is a guess for an agent.

  2. Label every form field

    Each field needs a visible label tied to it: First name, Email, Phone, Preferred location. Placeholder text that disappears when you type is not a label.

  3. Keep the booking on a page, not a pop-up maze

    Booking widgets that open in nested pop-ups, new windows or iframes that load slowly are where agents stall. If your platform offers a plain booking page, link to it.

  4. Show times and prices as text

    A schedule that is a picture, or prices that only appear after three clicks, cannot be compared. The agent moves on to the studio whose times it can read.

  5. Check your bot wall

    A challenge page built to stop software also stops the software your customer sent. Make sure your security settings let a normal signed-in browser through to the schedule and the form.

  6. Make the last step a person's step

    Agents hand payment and final confirmation back to the human. Make that final screen short and clear, so the person who takes over can finish in one tap.

None of this is new advice for accessibility. Clear labels, real buttons and readable schedules have always helped people using screen readers. The difference now is that the same fixes also decide whether an agent can finish the job. The four questions an AI agent asks your website covers the rest of the checklist.

Where this goes next

The agent browser is a small slice of how people find a business today, and most of these products are still in preview, paid tiers or limited regions. But the direction is clear from what the makers did this year: the agent moved into the browser people already use, and it fills in forms. The business whose form works gets the booking.

That raises a harder question. If agents now look like customers, which ones should you let in, and how would you even tell? In Part 9, Who gets through the door, we look at agent identity, bot walls and the new ways sites are deciding which software to trust. If you missed the start of the series, Part 1 makes the case that this shift is already measurable.


Sources

  • Perplexity's Comet launch and free availability: Engadget, "Perplexity's Comet AI browser is now free for everyone," October 2, 2025. engadget.com
  • Microsoft Edge Blog, "Introducing Copilot Mode in Edge: A new way to browse the web," July 28, 2025. blogs.windows.com
  • Microsoft Edge Blog, "New updates to Edge across desktop and mobile," May 13, 2026 (Copilot Mode retired, Browse with Copilot). blogs.windows.com
  • Opera Newsroom, "Opera ships the Opera Neon AI agentic browser," September 30, 2025. press.opera.com
  • Thurrott, "Opera Neon is Now Available," December 11, 2025 (US price). thurrott.com
  • TechCrunch, "OpenAI is shutting down Atlas, but its AI browser ambitions are still growing," July 9, 2026. techcrunch.com
  • OpenAI Developer Community, "Atlas is scheduled to stop working on August 9, 2026," August 7, 2026, quoting OpenAI's notice. community.openai.com
  • OpenAI Help Center, "Evolving Atlas into ChatGPT for browser-based agentic work" (deprecation wording as quoted in search results; page blocked automated reading). help.openai.com
  • TechCrunch, "OpenAI says AI browsers may always be vulnerable to prompt injection attacks," December 22, 2025, reporting OpenAI's post on hardening Atlas. techcrunch.com
  • 9to5Google, Chrome auto browse launch, January 28, 2026. 9to5google.com
  • Google, "The new era of browsing: Putting Gemini to work in Chrome." blog.google
  • Google, Gemini in Chrome with auto browse on Android, August 18, 2026. blog.google
  • Google, "Architecting security for agentic capabilities in Chrome," December 8, 2025. blog.google
  • Anthropic, "Claude in Chrome is generally available," August 26, 2026. claude.com
  • Brave, "Agentic browser security: indirect prompt injection in Perplexity Comet," August 20, 2025. brave.com
  • Atlassian, "Atlassian Completes Acquisition of The Browser Company of New York," October 21, 2025, via Stock Titan. stocktitan.net
  • Dia product site, availability. diabrowser.com
  • BrightEdge, "ChatGPT Referral Traffic More Than Doubles in 2026," September 24, 2026. brightedge.com

See your own locations in it.

Book a walkthrough with David Steel. Bring last month's lead count and one location you are worried about.