---
title: "Agent map October 2026: four kinds of AI visitors · Specoria"
description: "Over 60 browser and computer-use agents exist, but few tell your store who they are. A field guide to the four identity classes and what to do about each."
source_url: "https://specoria.com/insights/the-agent-map-october-2026/"
lang: "en"
---

[← All insights](https://specoria.com/insights/)
Market map October 7, 2026 6 min read

# The agent map, October 2026: four kinds of AI visitors, and the majority you can't see

More than 60 browser and computer-use agents are on the market, but only a few tell your store who they are. A field guide to the four identity classes, what changed this year, and what to do about each.

[Specoria Team](https://specoria.com/about/)

By October 2026 there are more than 60 browser and computer-use agents on the market: AI-native browsers, assistants built into Chrome and Edge, developer APIs and the cloud infrastructure that runs them. For a store, the most important question about all of them is a simple one: when one of these agents visits, can you tell?

Mostly, you can't. Only a small group identifies itself cryptographically. The rest either name themselves in a header anyone can copy, or look exactly like an ordinary Chrome visitor. This article sorts the market by that one property, because it decides what a store can actually do.

## The market is consolidating for shoppers and growing for developers

Several well-known products shut down or were folded into larger ones this year:

- **ChatGPT Atlas** stopped working on 9 August 2026, 292 days after launch. Its agent features moved into the ChatGPT desktop app, a Chrome extension and Codex.
- **Google Project Mariner** ended on 4 May 2026; Google says its technology was handed over to other Google products.
- **Edge Copilot Mode** was retired on 13 May 2026 and its features were built into Edge itself.

In their place, agents moved into the browser people already use, or into the chat app. ChatGPT Work (9 July 2026) runs a cloud browser, Gemini in Chrome can browse on its own ("auto browse"), and Claude in Chrome became generally available on 26 August 2026. At OpenAI's DevDay on 29 September 2026, "dots" arrived: always-on agents, each with its own cloud computer.

On the developer side the market keeps growing. New browsers such as Polar and Aside launched, Hark previewed its Handoff agent on 5 August 2026, and infrastructure companies such as Browserbase, Steel and Kernel run agents at scale.

## Class 1: signed cloud agents (high trust)

**Examples:** ChatGPT Work's cloud browser and dots, part of Google-Agent's traffic, Browserbase, Amazon Bedrock AgentCore Browser.

These agents sign every request with HTTP Message Signatures (RFC 9421). OpenAI's help centre documents that ChatGPT Work's cloud browser signs each request with the Signature-Agent value "https://chatgpt.com". Google signs only "a subset" of Google-Agent requests, as "https://agent.bot.goog". A store or CDN can check the signature against keys published at a well-known address, so the identity cannot be faked.

Cloudflare has handled signed agents as verified bots since 1 July 2026, labelling them "Direct" or "Intermediary".

**What to do:** allowlist these signatures in your bot protection, and make sure they are not challenged on product, cart and checkout pages.

## Class 2: declared user-triggered fetchers (medium trust)

**Examples:** ChatGPT-User, Claude-User, Perplexity-User, Google-Agent, MistralAI-User, meta-externalfetcher.

When someone asks an assistant a question, these fetchers read your page at that moment and name themselves in the user-agent string. You can verify them against the provider's published IP ranges or reverse DNS, but the name itself can be copied. They also differ on robots.txt: Claude-User follows it, while OpenAI says robots.txt "may not apply" to ChatGPT-User, and Google-Agent does not apply it.

**What to do:** open product and policy pages to these fetchers in robots.txt, and let them through bot protection with IP verification rather than by name alone.

## Class 3: agents inside the shopper's own browser (low trust, highest volume)

**Examples:** Perplexity Comet, Claude in Chrome, Gemini auto browse, Edge Copilot, Dia, Opera Neon, Polar, Aside, the Manus browser extension.

These agents run in the shopper's own browser, with the shopper's own sessions. At network level they are almost impossible to tell apart from a person. HUMAN Security notes that Comet "does not provide a verifiable per-request identity signal", and Perplexity's documentation lists no Comet-specific user agent.

This is where most agent traffic is likely to come from, and no allowlist will help you recognise it. What decides whether it converts is the site itself: an accessible page structure, clear form labels, product and price data readable without JavaScript, and a checkout step the human confirms.

**What to do:** treat "usable by an agent" as a conversion requirement. That is exactly what a readiness test measures.

## Class 4: stealth-focused cloud agents (low trust)

**Examples:** Hark Handoff (its identity policy has not been disclosed), Browser Use Cloud, Hyperbrowser, Browserless, Bright Data's Browser API.

Some infrastructure is built to look human, with proxy rotation and CAPTCHA solving. Only behavioural bot detection catches it. Hark, which ranks first on the Online-Mind2Web human-evaluated leaderboard, has not said how its agent identifies itself to sites.

**What to do:** apply stricter checks to unsigned traffic at checkout and account steps, but keep catalogue and policy pages readable.

## A new door: WebMCP

For class 3 agents there is a newer option. WebMCP lets a site expose actions such as "add to cart" or "check stock" as tools an agent in the browser can call directly, instead of guessing which button to press. It is in origin trial in Chrome 149; ChatGPT added support in August 2026, and Cloudflare Browser Run and Opera Neon support it too. It is early, but it is the most concrete way for a store to speak to agents it cannot identify.

## The bottom line

Recognise the agents that prove who they are, verify the ones that announce themselves, and make your store work for the ones you will never see. The first two are settings in your CDN. The third is your storefront.

Specoria's agent simulation runs Claude, GPT and Gemini model families in a real, unsigned Chromium browser, the closest setup to class 3 agents, and shows step by step where they get stuck. Start with a [free readiness test](https://specoria.com/#contact).

### Sources

- Cloudflare, [The age of agents: cryptographically recognizing agent traffic](https://blog.cloudflare.com/signed-agents/).
- Cloudflare, [Verified bots](https://developers.cloudflare.com/bots/concepts/bot/verified-bots/).
- OpenAI Help Center, [ChatGPT Work's Cloud browser allowlisting](https://help.openai.com/en/articles/11845367-chatgpt-agent-allowlisting).
- Google Search Central, [Authenticating requests with Web Bot Auth (experimental)](https://developers.google.com/crawling/docs/crawlers-fetchers/web-bot-auth).
- Perplexity, [Perplexity crawlers](https://docs.perplexity.ai/docs/resources/perplexity-crawlers).
- HUMAN Security, [What is Perplexity Comet and why is it on my website?](https://www.humansecurity.com/ai-agent/perplexity-comet/)
- TechCrunch, [Hark previews its browser use agent for completing tasks](https://techcrunch.com/2026/08/05/hark-previews-its-browser-use-agent-for-completing-tasks/), August 5, 2026.
- TechCrunch, [Perplexity employee who worked on Comet launches an AI browser aimed at knowledge work](https://techcrunch.com/2026/07/29/perplexity-employee-who-worked-on-comet-launches-an-ai-browser-aimed-at-knowledge-work/), July 29, 2026.
- Opera, [Your AI agents can use Opera Neon free of charge](https://blogs.opera.com/news/2026/08/your-ai-agents-can-use-opera-neon-free-of-charge/), August 2026.
- Hark, [Introducing Hark Handoff](https://hark.com/articles/introducing-hark-handoff).

## Related

- [Shopify opened checkout to browser agents. What WebMCP means for every other store](https://specoria.com/insights/shopify-opens-checkout-to-browser-agents-webmcp/)
- [The Turkish checkout through an AI agent's eyes: seven obstacles and how to fix them](https://specoria.com/insights/turkish-checkout-through-an-ai-agents-eyes/)
- [What tires a shopping agent: 33 frictions that slow AI agents down in your store](https://specoria.com/insights/what-tires-a-shopping-agent/)
- [Agent protocol map: UCP, ACP, AP2, MCP, WebMCP](https://specoria.com/agent-protocols/) What each protocol does and what the free test checks
- [Scan API, MCP server and GitHub Action](https://specoria.com/developers/) Run the free test from your own scripts or CI

FREE TEST

## Is your store ready for shopping agents?

See in seconds how a shopping agent reads your store: free, instant, no email needed.

The free test runs in your browser and needs JavaScript. [Request the free deep audit by email instead →](https://specoria.com/#contact)

Your result opens on its own page. Want the full picture? The free deep audit and panel come next, by email.
