Issue #278

Browser Agents Click Like Humans—Law Hasn't Caught Up

Sites that block crawlers still open their doors to AI agents that operate a browser just like a person would.

BusinessBrowser Agents Click Like Humans—Law Hasn't Caught Up

OpenAI Shut Down Its Browser, Anthropic Went Full Launch

AI agents that operate browsers on people’s behalf went through three major events in the summer of 2026. OpenAI shut down ChatGPT Atlas, the AI browser it had launched on October 21, 2025, on August 9, 2026, and moved the in-browser agent functionality to the ChatGPT desktop app, a Chrome extension, and Codex. Anthropic took Claude in Chrome, which it had started as a research preview in August 2025, and rolled it out fully to all paid plans on August 26, 2026. In between, in June, Aside—a startup from Y Combinator’s1 Fall 2025 batch—released a Chromium-based browser that operates logged-in sites on a person’s behalf.

All three events point in the same direction. The way AI accesses websites is shifting from a “program that scrapes data” to a “hand that operates the browser a person actually uses.” This piece explains why that shift is happening now, why current law still can’t judge this behavior, and what site operators and agent users alike need to reconsider as a result.


Not Breaking Down the Blocked Door—Walking In Through the Human One

The mechanism is simple. For the past several years, web services have spent money blocking automated access. They blocked crawler IPs, detected the fingerprints of automation tools like Selenium and headless browsers2 that run without a display, and threw up CAPTCHAs whenever something looked suspicious. This defense rests on a single premise: that an automated program and a human’s browser look different.

Browser-operating agents sidestep that premise entirely. They open the exact same browser window the user normally uses, reuse the user’s cookies and login session as-is, and view, click, and type on pages the way a person would. From the server’s perspective, it’s just a request coming in as usual, from the device that user always connects from. The “bot-like signatures” that used to justify blocking simply aren’t there. Aside put exactly this at the center of its product pitch: instead of bolting on an API integration, it actually logs into email, dashboards, and internal tools to get the work done. Anthropic, too, cited internal dashboards without official integrations, legacy systems, and partner portals as use cases for Claude in Chrome.

The reaction I’ve seen over the past few weeks has been intense. Things people assumed were impossible are suddenly possible. Repetitive processing on government administrative sites, gathering product information from specific shopping malls, and accessing sites where crawling itself had been blocked were the leading examples. That said, these are usage scenes I’ve observed, and they differ from what each product officially permits. Anthropic has blocked financial-service sites by default since the 2025 preview, and Aside likewise requires human approval for actions like payments, posting, and sending. What matters for this piece isn’t the products’ safety guardrails, but the underlying structure: the moment previously-blocked access hides behind a user’s login, the server loses any means of telling it apart.

The Law Has Only Ruled on Crawling So Far

If you ask whether this is legal, there’s no clear answer. No one has ever defined this kind of behavior. When I asked a few lawyers I know, I got the same response: if you had to pin it on something, it would be closest to obstruction of business, but under current law it sits in a gray zone that’s hard to name. Selling the information you collect that way for profit, though, would be a different story.

The case where Korean courts have dealt with automated access most deeply is the crawling dispute between Yeogiyeottae and Yanolja, two Korean accommodation-booking platforms. Yeogiyeottae’s founder and staff were indicted in March 2019 on charges of accessing Yanolja’s servers roughly 15.94 million times between June and October 2016 using a crawling program, collecting lists of partner lodgings, prices, and discount information. On May 12, 2022, the Supreme Court finalized a not-guilty verdict on all counts—unauthorized intrusion into an information and communications network, obstruction of business by computer, and copyright infringement (Case No. 2021Do1533). The standard the Supreme Court established was this: the party that defines access rights is the service provider, and whether the provider restricted access is judged by weighing outward, observable circumstances—things like protective measures or terms of service. In this case, ordinary users could freely access the same server through the app, and since there were no protective measures blocking access, the court ruled it was not an intrusion. Obstruction of business by computer also requires proof that information processing actually malfunctioned, and no such proof existed.

The civil case reached a different conclusion. On August 19, 2021, the Seoul Central District Court ruled that Yeogiyeottae’s unauthorized use of lodging information Yanolja had built up through substantial investment constituted misappropriation of achievements under the Unfair Competition Prevention Act3, awarding ₩1,000,000,000 (~$730,000) in damages. The Seoul High Court upheld this ruling on August 25, 2022. The appellate court held that the fact information could also be obtained through normal access didn’t make its use permissible, and that liability for damages remained even without proof of server failure.

Holding this precedent up against browser-operating agents shows where the axis of judgment actually sits. In the criminal case, the crux of the acquittal was “access wasn’t blocked” and “anyone could view it.” But most of the sites agents access today are ones that are locked down. The agent, though, isn’t breaching that defense—it’s using the user’s own account and browser to view only the screens the user already has the right to see. The Supreme Court’s standard presumes access by an unauthorized third party, whereas here, it’s a tool belonging to an already-authorized user that’s doing the moving. If a site inserts a “no automated tools” clause into its terms of service, that could, under the Supreme Court’s standard, count as grounds for restricting access—but since such a session is indistinguishable from a human one, the technical basis for catching a violation is weak, and whether a user’s own tool has exceeded its permitted scope has never actually been ruled on. The civil-law axis, by contrast, isn’t about the method of access—it’s about the outcome: what was done with someone else’s achievements after taking them, whether it placed a burden on the server. I think this is exactly why the lawyers I spoke to reached for obstruction of business and unfair competition first.

The situation in the United States is similar. The hiQ v. LinkedIn case, which dealt with crawling public profiles, was settled in the direction of “accessing publicly available information is not computer intrusion,” but an agent operating inside a user’s own logged-in session is not the situation that case addressed. To sum up: the law has ruled on “programs that entered without permission,” but it hasn’t yet ruled on “programs that borrow the hands of someone who already has permission.”

The internet is splitting into two roads

I wrote in my April ZDNet Korea column, 15 Years On, the Web’s Gatekeeper Is About to Collapse, that the question “are you a robot?” had stopped being worth asking. Part of the reason was that CAPTCHA had been technically cracked, but the bigger reason was that the bot-versus-human binary no longer explained traffic patterns. According to Cloudflare’s December 2025 report, human-generated traffic accounted for just 43.5% of all HTML requests. Then, in its Q2 2026 earnings release on August 6, 2026, Cloudflare disclosed that non-human requests had, for the first time, crossed 50% of traffic on its network. Revenue for the same quarter came to $696.1 million, up 36% year-over-year, and the company cited demand for security and payment products handling AI agent traffic as a driver of that growth.

Browser-operating agents add another layer to this trend. What Cloudflare’s statistics classify as “non-human requests” is traffic identified as bots. Agents operating inside a user’s own browser are likely to be counted on the human side of that ledger. Which means the real share of automated traffic is higher than the statistics show — and the gap will only widen from here.

That’s why I think the internet is splitting into two roads. One is the highway for agents. This is the road where automated access gets an identity and a toll and is let through legitimately — think of the agent wallets and name tags Cloudflare rolled out in August, or Web Bot Auth4, which attaches cryptographic signatures to crawlers. I covered this road in detail in Issue 184. The other is the human-only road. This is the road with content locked behind logins, device verification requirements, and barriers built directly into access itself. Companies like Cloudflare that sell security solutions are thriving precisely because both roads need constant construction work.

The problem browser-operating agents create sits on the second road. We built a human-only road, and now agents are walking it wearing human clothes. Raise the barriers and real humans get inconvenienced; lower them and you can’t tell the difference anymore. The conclusion from my column comes right back around: the question isn’t whether something is a robot, but what this access is trying to do, and with what intent. And yet the standards for answering that question are still being built almost entirely on the side of traffic already identified as bots.

Oswarld’s Lens

People are calling this shift the moment customers become agents, the dawn of an era where agents trade with agents. I don’t think that’s some new future. It already happened, long ago, in the stock market. Program trading and quant trading were exactly that. A market where algorithms — not people — place orders against other algorithms, read each other in milliseconds, and leave humans to observe the results after the fact has existed for decades. To anyone unfamiliar with how futures markets operate, agent-to-agent trading might look novel, but people in finance who have already seen the limits of that market know what tends to happen next.

Here’s my read: even a market where algorithms trade with each other eventually reverts to a market of people, an irrational market. Markets look rational, but they always end up revealing irrational decisions in the final analysis. That’s not because individual participants are irrational. It’s an emergent result — when a crowd of participants, each acting rationally on their own, comes together, the whole behaves differently. Just as program trading made markets more efficient without eliminating crashes and manias, an era where agents roam the web on our behalf won’t lead to some frictionless market with human judgment removed from the equation.

robotsThis isn’t a conclusion that’s been proven yet in the browser-agent market, and there’s no guarantee that the history of automation in finance will simply repeat itself on the web. But before we get excited about a new buzzword like A2A, I’d suggest we first look at how the algorithmic market — which has already been running for decades — actually played out.

Closing

To sum up, there are three things here. Browser-operating agents don’t break through defenses — they walk in behind the user’s own login, which is why existing bot-blocking measures don’t work on them. Korean courts have ruled on “a program that scraped publicly available information that wasn’t blocked,” but they haven’t yet ruled on “a program that operates an authorized person’s browser on their behalf.” And the internet is splitting into a high-speed lane for agents and a lane reserved for humans — but this kind of agent is still driving on the human lane.

If you run a website, check whether your bot policy rests on the assumption that “a human session means a human.” That assumption has already broken down. If you use an agent, remember the opposite: everything that agent does is legally recorded as an action taken by you, Reader. Saying an area has no law doesn’t mean there’s no liability — it means that when something goes wrong, nobody yet knows which law will apply.


💬 If you’ve ever used a browser agent to do something a site “normally wouldn’t allow,” tell me which site it was and what you had it do.

📨 Send this piece to whoever handles bot-blocking or scraping policy at your company. It might give them a reason to revisit the assumptions their policy is built on.


Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

Primary sources

Related past issues

Illustrated portrait of Kwangseob Ahn (Oswarld)

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

📝 Glossary

각주

  1. Y Combinator: A US startup accelerator. It invests in early-stage startups by batch and runs them through a three-month program. Aside is part of the Fall 2025 (F25) batch. ↩

  2. Headless browser: A browser that fetches and processes web pages in the background without rendering a screen. It’s widely used for crawling and automated testing, and detection techniques to block it have advanced in tandem. ↩

  3. Unfair Competition Prevention Act: Officially the Unfair Competition Prevention and Trade Secret Protection Act. It defines unfair competition as unauthorized use, in a manner contrary to fair commercial practice, of results created through another party’s substantial investment or effort, and allows claims for injunctions and damages. At the time of the Yeogieotte ruling, the relevant clause was Article 2, Item 1, Subitem (Ka); subsequent amendments may have renumbered it. ↩

  4. Web Bot Auth: A method by which bot operators attach cryptographic signatures to their crawler’s requests to prove identity. It uses the HTTP Message Signatures standard and has been adopted by Cloudflare, Google, OpenAI, and others. ↩