Scraping is inference. The agent downloads a page built for human eyes, guesses which button submits the order, and clicks where it thinks that button sits. Layouts shift and the guess breaks. Also, nobody on the other side agreed to any of it. Robots.txt, the file where a site lists what crawlers should skip, was standardized only in 2022, and written for search engines. It asks; it can't refuse.
A Chrome origin trial is testing the other arrangement. WebMCP, proposed by Google and Microsoft engineers, lets a site publish its own search and checkout functions as tools an agent calls directly, the way a business partner calls an API.
Reliability is what the demos show. The change worth watching is that the site becomes a counterparty. Cloudflare already treats agent traffic as a category a business can price, permit, or block. A published surface carries terms, and terms can be withdrawn.
Permission isn't fidelity, though. A site can verify an agent was authorized to buy and still have no idea whether it understood what its human wanted.
Where the standard stands: WebMCP is a W3C community-group proposal, not an approved standard. Live in a Chrome 149 trial. Firefox and Safari haven't committed.
Who's testing it: Expedia, Booking.com, Shopify, Etsy, Instacart, Target, Redfin, TurboTax, Credit Karma.
Telling agents apart is getting cheap: A June 2026 study combining network, TLS, header, and JavaScript signals reported 0.993 accuracy sorting humans, scrapers, automation frameworks, and six LLM-based agents. Some agents beat every anti-bot defense tested and were identified anyway.
Competing protocols: A W3C/GS1 workshop in September asks how retailers stay visible across MCP, Google's UCP, and OpenAI's ACP — and whether the web fragments into semi-closed agent ecosystems.
Identity work underway: NIST, FIDO, and IETF groups are all treating agent identity, delegation scope, and audit records as unsolved infrastructure problems.

