← Back to news
Archived · Published 4 August 2026
Agentic Browsing Moves From Research Demo to Shipping Product as Google and Perplexity Race to Ship AI-Driven Browsers
Agentic browsing — an AI system that can navigate a live website, click through multi-step flows, and complete tasks like booking a reservation or filling out a form without a human driving each step — has moved from limited research previews into wider consumer availability through 2026, with Google's Project Mariner lineage and Perplexity's Comet browser both expanding from early-access waitlists to general availability this year. The core technical challenge these products are built around is the same one that made earlier "AI browser extension" attempts unreliable: real websites change their layout constantly and are full of ads, cookie banners, and dynamic content that can derail a rigid automation script, requiring the agent to interpret the page visually and adapt in real time rather than relying on a fixed set of selectors.
The use cases driving actual daily usage skew toward well-bounded, repetitive tasks rather than open-ended web browsing — price comparison across multiple retailer sites, form-filling for routine account tasks, and monitoring specific pages for changes — a pattern similar to the narrow-authority approach that made autonomous customer-service agents viable, where the agent's usefulness comes from handling bounded, low-risk-of-error tasks reliably rather than attempting fully general web navigation.
The friction point publishers and website operators have raised is bot traffic classification: agentic browsers generate page loads and interactions that look similar to legitimate human browsing but at different behavioral patterns, complicating the existing bot-detection infrastructure most commercial websites rely on, and pushing some publishers toward explicit API or data-licensing arrangements with the AI browser vendors rather than leaving agentic traffic to route through the same channel as ordinary visitors.
Security researchers have also flagged prompt-injection risk as the primary open problem for this category: a malicious or compromised webpage can embed instructions in its content aimed at hijacking the agent's task rather than the human user's intent, a vulnerability class that doesn't have a fully solved defense yet and that vendors describe as the main blocker to expanding agentic browsing into higher-stakes tasks like account changes or payments.
Defici Editorial · Tech News
This article was generated by Defici's AI editorial system.