← Google News

This AI Can Now Log Into Websites for You. But Should You Let It? - inc.com

Google News · July 16, 2026
This AI Can Now Log Into Websites for You. But Should You Let It? inc.com [truncated: Google News RSS provides only a snippet, not full article

Detailed Analysis

Anthropic's Claude has moved into a new phase of functional autonomy: the ability to log into websites and interact with them on a user's behalf, using stored credentials to navigate authenticated sessions rather than simply reading and summarizing publicly available content. This capability, built on Anthropic's "computer use" and browser-agent tooling, represents a meaningful escalation from Claude acting as a conversational assistant to Claude acting as an operator—filling out forms, clicking through workflows, and executing multi-step tasks inside accounts that require sign-in. For users, the appeal is obvious: an AI that can manage subscriptions, book appointments, check account balances, or handle repetitive administrative chores without a human driving every click.

The trade-off, and the reason coverage like this Inc. piece frames the development with a cautionary "but should you?" is trust and security exposure. Granting an AI agent login credentials means extending it a level of access previously reserved for the account holder alone, which raises questions about credential storage, session hijacking risk, prompt-injection attacks embedded in malicious web pages, and the possibility of the agent misinterpreting instructions and taking unintended actions—deleting data, making purchases, or sending messages a user never authorized. Anthropic has been vocal about these risks industry-wide, publishing research on agentic misuse and building in safeguards such as permission confirmations, sandboxing, and limits on sensitive actions, but the fundamental tension remains: the more autonomy an agent has, the more damage a mistake or exploit can cause.

This shift matters because it signals where the AI industry is heading: away from chatbots that answer questions and toward agents that complete tasks end-to-end across the open web. Anthropic, OpenAI, and Google have all been racing to ship browser-controlling agents (Claude's computer-use API, OpenAI's Operator, Google's Project Mastra and Gemini-powered agents), betting that "doing" rather than "chatting" is the next major value driver and revenue lever for enterprise and consumer AI products. Login-capable agents are a natural, almost inevitable extension of that ambition, since so much of the useful internet sits behind authentication walls—banking, shopping, SaaS dashboards, healthcare portals.

At the same time, this development intensifies an industry-wide reckoning over agent safety infrastructure that hasn't fully matured. Standards for how agents should authenticate, what scopes of access they should be granted, how actions get audited, and how liability is assigned when something goes wrong are still being worked out in real time, largely through vendor policy rather than regulation. Anthropic's own responsible-scaling commitments and constitutional AI framework are being tested precisely in these agentic, credentialed contexts, where the cost of an error is no longer a bad answer but a real-world action taken with a user's identity. The Inc. article's framing—capability paired with hesitation—captures the current moment accurately: the technology has arrived faster than the guardrails and user intuitions needed to trust it fully.

Read original article →