Computer and browser actions on the AI Agents track. Clicking a real UI is a high-risk tool. Screens change, buttons move, and a wrong click can buy something. Prefer APIs. Use UI control only when no API exists, inside a sandbox, with a person on risky clicks.
This lesson assumes you already worked through Agents that search knowledge.
The idea in practice
Give the agent a screenshot or accessibility tree, a short list of allowed actions, and a domain allow-list. Block payments and account deletion.
A concrete check
goal = {
'track': 'AI Agents',
'lesson': 'Computer and browser actions',
}
checks = [
'input available at decision time',
'score matches the real decision',
'failure case written down',
]
print(goal['lesson'])
for item in checks:
print('-', item)
Run the sketch locally if you have Python. The printout is a reminder of the checks, not a trained model. Replace the strings with the real inputs from your own example before you treat it as a design.
What usually goes wrong
An agent with a logged-in browser and no allow-list can wander into settings or purchase flows. When this happens, stop adding parameters or tools. Fix the check, the data, or the permission, then run the same example again.
What to write down
- The input you are allowed to use at decision time.
- The output and the score or pass rule.
- One failure you will test on purpose.
- What you will not claim the system can do.
Practice
List what you would block in a browser sandbox for a 'check order status' agent.
Self-check
- Say Computer and browser actions in one sentence that mentions an input and an output.
- Name the failure mode in this lesson and the check that would catch it.
Done when: you can explain this lesson without the page open, and you have a written failure case.