To content
goeke.digitalSMART DIGITAL CREATIVE

COLLABORATION

Depending on the task, the starting point can vary.

Four formats. No mandatory steps.

View collaboration
Websites and digital systems

Websites for people, search engines, and digital agents

In May 2026, company websites had to be not only readable and findable in search results. First browser and computer agents could also, on behalf of users, operate forms, transfer information, and execute clearly defined website functions.

In this post

Websites are increasingly read and used on behalf of others

A website for humans, search systems, and digital agents does not require three separate interfaces. It requires a common, resilient architecture of understandable content, semantic structure, technical accessibility, stable interactions, and clear security boundaries.

Humans must be able to understand and decide. Search systems must be able to access content and relationships. Agents may only reliably perform actions that are explicitly intended, controlled, and traceable. Agent Readiness therefore begins with proven web quality and does not end with a new protocol.

Starting point

By May 2026, digital agents had visibly made the leap from mere response to action. In 2025, OpenAI had introduced Computer-Using Agent and later ChatGPT Agent systems capable of operating websites and graphical interfaces. Other providers developed comparable computer-use functions.

At the same time, web standardization began to react to this usage. Chrome development introduced WebMCP in February 2026 as an early proposal. In May, the concept was explained at Google I/O as a planned open web standard. Websites should be able to describe functions as structured tools for browser agents, rather than relying solely on agents for visual recognition and simulated clicks.

WebMCP was not a widespread standard at that time. Early development was nevertheless strategically relevant. It showed that websites could not only deliver content in the future, but could also explicitly describe released capabilities.

What lies behind the problem

Reading, conveying, and acting are different forms of use

A human interprets language, design, context, and consequences. They can recognize uncertainty, ask a follow-up question, or abort an action.

A search system accesses pages, links, content, and signals. It conveys information in search results or answer views, but does not necessarily perform a business action.

An agent can act additionally. It fills out a form, selects an option, or initiates a process. This turns information quality into a question of authorization, security, and process responsibility.

Those who mix these forms of use underestimate the risk. Good discoverability does not justify unrestricted scope of action. Machine-readable content does not automatically mean secure agent functions.

Graphical operation is possible, but error-prone

Computer-use systems can interpret screenshots and trigger mouse or keyboard actions. This method uses the same interface as a human. It is flexible but dependent on visual states, labels, loading times, pop-ups, and layout changes.

A human can classify an unusual hint. An agent can confuse a button or overlook an intermediate step. The more critical the action, the less its reliability should depend solely on visual reconstruction.

Structured tools change responsibility

WebMCP proposed in 2026 to explicitly describe website functions for agents. This can make operation faster and more reliable. It also increases the responsibility of website operators.

A released tool requires:

  • a clear purpose
  • understandable inputs
  • valid and limited parameters
  • recognizable effects
  • Error handling
  • Authorization and security rules
  • comprehensible logging

The website thus not only explains to the agent where to click. It explains which action is permissible and how it is technically executed.

The logged-in context increases the risk

Browser agents can operate within an authenticated session. This may give them access to personal data, accounts, shopping carts, internal areas, or stored payment and contact details.

This capability is useful and sensitive. Website content or embedded third-party components can try to move agents to unwanted actions. Security concepts must therefore explicitly consider untrusted content, permissions, confirmation, and sensitive actions.

Strategic Classification

The human website remains the reference

An agent-enabled website must not come at the expense of human usability. The visible interface remains the reference for meaning, offering, conditions, and consequences.

Semantic HTML, accessible forms, and clear status messages help all three user types. They support people with assistive technologies, make it easier for search systems to interpret, and provide agents with more stable cues.

A new agent protocol should complement this foundation, not bypass it.

Three levels must be planned separately

A robust architecture distinguishes:

  1. Comprehension level. Visible content, navigation, receipts, conditions, and consequences.
  2. Exploration level. HTML semantics, internal links, metadata, structured data, technical accessibility.
  3. Action level. Forms, APIs, or agentic tools with permissions, validation, confirmation, and logging.

The layers build on each other. An action without understandable meaning is risky. A technically perfect tool must not trigger a process that the user cannot comprehend.

Agent-enabled functions require a selection strategy

Not every website function should be exposed to agents. Initially, clearly defined, reversible, or low-risk tasks are suitable, for example:

  • Filter information in a product catalog
  • query available appointments
  • prepare a draft for a form
  • submit a request with explicit confirmation
  • select publicly available documents

Critical actions require additional control. Contract conclusion, payment release, account changes, sensitive data transfer, or binding bookings must not be triggered by an unclear agent action alone.

Visible and machine statements must match

An agent tool must not hide conditions that are not visible on the website. Inputs, prices, availability, data protection, and consequences must be consistent.

This agreement is a governance issue. Marketing, development, legal, sales, and operations must jointly define which function promises what and who is responsible for errors.

Perspective from practice

For most medium-sized business websites, the priority in May 2026 was not immediate WebMCP implementation. The bigger levers remained in fundamental quality:

  • clear performance and contact channels
  • clean semantic structure
  • stable forms
  • traceable confirmations
  • consistent data and content
  • clearly regulated responsibilities
  • Protection of critical actions

A website with unclear forms will not improve through agent access. It may only automate its own ambiguity.

A step-by-step approach was sensible. First, existing interactions were documented and tested. Then, suitable agent scenarios could be identified. Experimental standards were only checked where a concrete benefit and a justifiable limit were apparent.

The three-layer model of the agent-enabled website

The model prevents two false assumptions. First, good visibility is not sufficient for secure interaction. Second, a technical agent interface must not be separated from the visible user experience.

Framework of action

1. Secure existing web quality

Check semantic structure, accessibility, forms, status messages, internal links, and technical stability. These fundamentals have business value regardless of agents.

2. Inventory usage types

Separate direct human use, search and response mediation, and possible agentic actions. Document purpose, data, and risk for each form.

3. Select agent scenarios

Start with clearly defined tasks. Assess reversibility, data scope, potential for misuse, and the necessary degree of confirmation.

4. Clearly describe tools and inputs

Use clear names, limited input schemas, and understandable results. An agent should not have to find out what a function does through trial and error.

5. Have critical steps confirmed

Sensitive or binding actions require explicit confirmation by the user or other appropriate release. The agent may not infer intent from mere navigation.

6. Log and test

Document calls, errors, and impacts. Test not only successful standard cases but also ambiguous inputs, manipulated content, aborted processes, and missing permissions.

What companies should not do

Companies should not use Agent Readiness as a new label for a normal website. The term requires a traceable review of action, authorization, and security.

Likewise, experimental standards should not be treated as already established requirements. WebMCP was a proposal in early implementation in May 2026. Strategic sense lay in observation and targeted testing, not widespread adoption without a use case.

The most dangerous reaction would be to offer agents as many functions as possible to appear modern. A larger scope of functions does not automatically increase utility. It initially increases the attack and error surface.

Consequences for companies

Websites are becoming a common infrastructure for human decision-making, machine mediation, and selected automated action. This development adds a new layer of responsibility to website strategy.

The viable order is: understandability first, then discoverability, then controlled action. Companies that follow this order can explore agentic possibilities without turning the website into an uncontrolled execution channel.

Subject-matter connection

Agent Readiness as an architectural and governance issue

A website strategy for agent readiness jointly evaluates content, semantics, interactions, permissions, risks, and suitable use cases. SDC Discovery creates the basis for decision-making. Complex implementation and ongoing management can subsequently be managed within an SDC partnership.

Sources and technical foundations (9)
  1. OpenAI, Computer-Using Agent, January 23, 2025. Open source
  2. OpenAI, Introducing ChatGPT agent: bridging research and action, July 17, 2025. Open source
  3. W3C, AI Agent Protocol Community Group, founded May 8, 2025. Open source
  4. Chrome for Developers, WebMCP is available for early preview, February 10, 2026. Open source
  5. W3C Web Machine Learning Community Group, WebMCP discussion and draft status, February 19, 2026. Open source
  6. Chrome for Developers, WebMCP best practices, May 18, 2026. Open source
  7. Chrome for Developers, 15 updates from Google I/O 2026: Powering the agentic web, May 19, 2026. Open source
  8. Chrome for Developers, Agent security considerations for WebMCP, as of May 2026. Open source
  9. World Wide Web Consortium, ARIA Authoring Practices Guide. Open source
Göke Frerichs, digital strategist and Smart Digital Creative
Author

About Göke Frerichs

Göke Frerichs has been combining digital strategy, communication, technology, and implementation since 1999. As a digital strategist and Smart Digital Creative, he supports owner-managed B2B companies in developing clear and reliable digital systems from individual measures. His perspective is based on many years of consulting and implementation experience in the DACH region and North America.

More about Göke Frerichs
Website strategy and agent readiness

Clarifying the digital starting point

The right collaboration begins with a clear categorization.

Categorize collaboration