On 25 August 2026, OpenAI opened the browser built into the ChatGPT desktop app to WebMCP (official documentation), a protocol that lets a website itself expose the actions an agent may carry out on it. For any company that sells, takes bookings or handles requests online, being cited in an AI answer is no longer enough: the site also needs to be actionable directly from that answer.

The facts

  • Since 25 August 2026, WebMCP-compatible sites can offer structured tools to the ChatGPT desktop browser: document search, file editing, travel option comparison or basket filling. ChatGPT or Codex discover them automatically on the open page (Search Engine Journal).
  • The feature requires the GPT-5.6 Sol or Terra models; it is currently disabled on GPT-5.6 Luna, and remains unavailable in Enterprise and Edu workspaces. OpenAI states that WebMCP has no bearing on the ranking, citations or recommendations ChatGPT produces.
  • WebMCP is an experimental open standard: the specification is a draft from the W3C's Web Machine Learning Community Group, outside the official standards track. Google announced it in May 2026 for Chrome, where it remains behind an experimental flag. Millions of Shopify stores are already compatible, and Expedia, Instacart and Target are experimenting with it (VKTR).

How does WebMCP change the relationship between a website and an AI agent?

Before WebMCP, an agent browsed a site like a clumsy visitor: it clicked, typed and guessed the structure of the page at every step. With WebMCP, the site itself publishes a list of named JavaScript functions, each described and accompanied by a precise input schema. An arrow appears in the address bar to signal that a tool is available, and whether it can only read information or also change it. OpenAI states the intent plainly: the developer defines exactly how their application can be used, instead of leaving the agent to guess.

The protocol remains experimental and distinct from the “server” MCP launched by Anthropic at the end of 2024: it works only within the open page and the active session, and the tool disappears as soon as the tab is closed. OpenAI acknowledges real risks, including data exfiltration and prompt injection through a malicious tool description, and imposes a security check on every invocation as well as explicit confirmation before any purchase, deletion, message sending or sharing of personal information. That safeguard also shifts responsibility: the site decides what an agent may do on its pages, and the agent no longer makes it up on its own. It extends the logic of AI agents in business: value emerges when the scope of action is defined by whoever knows the business.

AIxH's view

Generative engine optimisation has so far concentrated on content: being cited, being understood, being picked up. WebMCP opens a second front, that of action, where a site that exposes its own tools keeps control over what an agent can do there. This criterion now sits alongside structured markup in our AI audit and integration in Luxembourg assignments: mapping the actions a site should expose, those it must forbid, and the confirmations to require. If you are wondering whether your site is ready for agents that act as well as for bots that read, a quick audit is usually enough to find out.

Follow our news? Add AIxH to your preferred sources on Google →

Also worth reading