AI Agents Are the New Browsers ? Make Your Links Catch Up
AI

AI Agents Are the New Browsers ? Make Your Links Catch Up

16 Sept 2026 12 min read

Something changed in AI this month, and it is bigger than another model release.

On 10 September, OpenAI released its Agents API in public beta. Instead of handing developers a model to call, it hands them infrastructure for long-running agents: durable sessions, tool use, context management, sandboxed environments and connections to MCP servers. Four days later the Agentic AI Foundation and Linux Foundation Education launched the Model Context Protocol Associate, the first official certification for MCP. And on 17-18 September, AGNTCon + MCPCon Europe brings protocol maintainers and platform teams to Amsterdam to discuss exactly this transition: agents moving out of prototypes and into production.

Three separate announcements, all pointing the same way. AI is moving from answering to doing - and once software starts doing things on our behalf, one of the oldest pieces of the web quietly becomes infrastructure again: the link.

The shift is not from bad chatbots to better chatbots

For the last few years most consumer AI followed one pattern. You typed something, the model answered, maybe it gave you a URL, maybe you copied the answer somewhere else. The AI stopped at the edge of the conversation.

Agents move that boundary. A useful agent opens files, calls an API, searches a database, uses another service, generates an artifact, creates a link, sends that link somewhere and keeps working. OpenAI describes the Agents API in exactly those terms: a layer that manages sessions and context while agents use tools inside sandboxes, with external MCP servers plugged in.

That sounds like a developer detail. It is not. It means the small actions humans currently perform between applications are turning into tool calls:

  • creating a short URL;
  • generating a QR code;
  • adding UTM parameters;
  • publishing something and handing the result to the next system.

The question is no longer whether an AI can produce a URL. The question is what happens after it does.

A link created by an agent has a different job

Humans are slow in useful ways. Before printing 5,000 flyers somebody normally sees the URL. Before putting a QR code on a menu somebody usually tests it. Before a campaign goes out somebody has a chance to notice that the tracking parameters are missing.

Agents remove those pauses. That is most of their value - and it also means the infrastructure behind the action has to carry more of the responsibility.

Picture an agent preparing a campaign. It writes the landing-page copy, generates three creative variations, creates the campaign URLs, drops them into a report and hands the assets to whoever runs distribution. The URL is not an incidental piece of text in that workflow: it needs an owner, it may need attribution, it may need to change later, it may need to be switched off. And if it was printed as a QR code, it can still be sitting in the physical world six months after the agent that created it has fallen out of everyone's context window.

That makes the link a control surface.

MCP is making small services callable

This is where the Model Context Protocol matters. MCP gives AI systems a standard way to discover and call external tools, instead of every service inventing its own integration. The ecosystem has grown far enough to have an official certification of its own, while broader agent interoperability standards such as A2A have attracted support from more than 150 organisations.

The important part is not the acronym, it is the architecture. A service no longer has to be something a human opens in another browser tab; it can be a capability available directly to an agent. URL shorteners, analytics platforms, file stores, CRMs and payment systems all become tools from the AI's point of view.

ShareCut already works this way. Its MCP server and developer API expose twelve tools, split on a deliberate line: anything a visit to the page would reveal anyway is free and needs no key - create_qr, expand_short_link, check_short_code - while anything that touches an account needs one. shorten_url creates a managed short link, update_link repoints one that has already been printed, and get_link_analytics reads the clicks back.

We wrote about one consequence of that shift already: AI assistants can now make a QR code so easily that nobody stops to ask whether the code is permanent. But there is a bigger question behind it. What happens when agents start creating links at scale?

Attribution gets much easier - if you design it in

Campaign tracking has always suffered from one extremely human problem: someone forgets. The team agrees that every LinkedIn campaign will carry utm_source=linkedin, utm_medium=social and a consistent campaign name. Then somebody is in a hurry, a raw URL gets pasted into a post, and three weeks later the traffic exists but nobody can say where it came from.

Agents can fix that, for an unglamorous reason. If link creation is a structured action rather than something copied out of a browser bar, attribution becomes part of the action itself. An agent can be instructed to always attach a source, medium, campaign and content identifier. A second agent can follow a different convention. A workflow can mint one tracked link per channel without anyone hand-editing a query string.

The agent does not need to remember your UTM convention. The system needs to enforce it. That is a small change with a large consequence: automation helps here not because AI makes analytics smarter, but because it makes good UTM hygiene boring and automatic.

And once those URLs pass through a controlled short-link layer, clicks are counted independently of the final destination. The landing page can move. The analytics property can change. The link stays the stable identifier for the campaign.

Reversibility matters more when software acts quickly

Speed is the main reason people want agents. Speed is also why mistakes get interesting. A human might create five links in an afternoon; an automated workflow can create hundreds before lunch. If the destination is wrong, an immutable output turns that into an expensive problem very quickly.

This is already obvious with printed QR codes. A static code carries its destination inside the pattern: once it is printed, changing where it goes means printing it again. A dynamic QR code points at an intermediate link instead, so the printed pattern stays the same while the destination behind it moves.

The same principle runs well past QR codes. Agent-generated infrastructure should favour reversible actions wherever a mistake is expensive. If a campaign URL has already been distributed, being able to repoint it beats generating a perfect new one. If a support document moves, the link does not have to move with it. If an event changes venue, the poster already on the wall should not become waste paper.

Agents make creation cheaper. That makes correction more important, not less.

The link layer is also a security boundary

There is a reason the agent conversation is increasingly a security conversation. When an AI can only generate text, its mistakes mostly stay text. When it can call tools, use credentials, reach systems and take external actions, the blast radius changes - which is why current agent infrastructure spends so much of its time on sandboxing, identity, permissions, auditing and governance.

Links sit inside that problem. A URL produced by an agent may be sent to a customer, pasted into a document, dropped into an automated message or turned into a QR code, and the recipient has to trust it. That makes several old-fashioned web properties newly important:

  • the destination should be checked, not merely accepted;
  • the domain should be recognisable to the person receiving it;
  • the owner should know which system created which link;
  • the action should be logged;
  • sensitive workflows should not depend on opaque URLs nobody can trace afterwards.

ShareCut screens every destination against Google Safe Browsing before accepting it - including on a change of destination, because a link screened once and then freely repointable is a delayed open redirect. Paid plans can serve links from the customer's own domain, and the short code itself is immutable through the API: the printed artwork encodes that exact URL, so it is the one thing a repoint may never touch.

None of that is uniquely AI. That is the point. The agentic web will lean heavily on infrastructure that was useful before agents existed; agents simply make its reliability matter more.

Machines do not care about readable URLs. Humans still do.

There is another tension worth noticing. An AI agent does not care whether the URL it receives is elegant - a random identifier works perfectly well for software. People behave differently. Someone deciding whether to tap a link in an email, scan a code in a restaurant or open something sent over WhatsApp is still reading small trust signals. Does the domain look familiar? Does the path make sense? Is this clearly connected to the organisation that sent it?

As more links get created automatically, there is a real risk that machine convenience produces a web that is hostile to humans: long query strings, anonymous redirectors, random identifiers and destinations nobody can guess before clicking.

The better model is not human-readable links instead of machine-readable infrastructure. It is both. Let the agent create the link programmatically; let the person receive something they can understand. Custom domains, deliberate short codes and clear destinations are the human-facing layer on top of automated plumbing.

QR codes are becoming a physical output of agents

The problem gets particularly interesting when links leave the screen. Ask an AI system for a QR code and the result can end up almost anywhere: a table tent, packaging, an event badge, a poster, a business card, a product label. A software action becomes a physical artifact - and physical artifacts have very different lifetimes from AI sessions. The conversation that produced the code may last an hour. The printed object may last three years.

Which is why generate a QR code is not quite a complete instruction. The useful questions are:

  • Should the destination be permanent?
  • Should scans be counted?
  • Is the destination likely to change?
  • Who controls the URL behind the code?
  • What happens if the original page disappears?

An agent can generate a static QR code in seconds, and static is often the right answer: Wi-Fi credentials, fixed text, one-time material, anywhere a redirect should not exist at all. But for a printed URL whose destination is expected to evolve, that extra layer of indirection is the thing that keeps the printed object useful.

The most useful agent workflow probably looks boring

There is a temptation to imagine agents doing spectacular things. Most of the real value will come from workflows that sound far less dramatic.

Imagine a marketing agent preparing a launch. It receives the campaign name and the landing page, then:

  1. creates one tracked URL each for LinkedIn, X, email and printed material;
  2. attaches consistent attribution parameters to all four;
  3. gives the print version an editable QR code and the digital versions readable short codes;
  4. records which campaign created them.

Two days later the landing page changes, and one update moves the destination behind every link instead of forcing each post, PDF and printed asset to be recreated. After the campaign, clicks and scans compare cleanly by channel.

There is no magic in any individual step. The improvement comes from removing the gaps between them. That is what agent infrastructure is actually about.

You probably do not need an AI version of every product

There is a product lesson in here too. Not every tool needs a chatbot. Often the better adaptation to the agentic web is simply making a reliable capability callable: create a link, generate a QR code, read the analytics, change the destination, return structured data, respect permissions, do the same thing every time.

MCP, REST APIs and agent tool systems make small capabilities like these disproportionately useful, because the human no longer has to stop, open another application and move information between systems by hand. The interface becomes optional. The capability remains.

That may be one of the bigger changes agents introduce. Software products will increasingly have two audiences at once: the human who needs to understand and control the system, and the agent that needs a predictable way to use it.

Where ShareCut fits

ShareCut started with a simple problem: long links are awkward to share. QR codes, analytics, editable destinations, custom domains, link-in-bio pages and digital menus were all built around that one primitive. Agents make the primitive interesting again.

The MCP server gives compatible AI clients QR generation with no key at all, because a static QR code is a commodity and putting it behind a gate would only make us worse than free. The paid difference is the part a hosted service can actually offer: a destination that stays editable after the artwork is printed, and a scan count that belongs to you. The Business plan adds the same capability over the REST API for conventional integrations.

The point is not to put AI into every link. It is to make links usable by AI without giving up the controls humans still need. The ideal result of an agent creating a URL is not an AI-generated link. It is simply a good link: trackable when tracking is useful, editable when change is likely, static when permanence and independence are preferable, readable when a human will see it, and owned by the person or organisation that depends on it.

The agentic web will still run on boring things

AI conversations gravitate toward models - which one reasons better, which one codes faster, which one has the larger context window. But as agents become normal users of software, the hard parts increasingly sit outside the model: authentication, permissions, observability, reliable APIs, identifiers, redirects, files, domains, links.

None of those is glamorous. They are the pieces that let an action survive after the AI has finished thinking.

The browser web gave humans a universal way to move between services. The emerging agentic web is building the same connective layer for software acting on our behalf. OpenAI's Agents API, MCP and A2A are different parts of that transition, and none of them makes the humble URL obsolete - they make it more important. When agents start creating, sharing and acting on links for us, the URL stops being the end of the answer and becomes part of the system.

Building with agents or MCP? ShareCut exposes QR generation through its MCP server and programmatic short-link creation through its developer tools, so the boring infrastructure is ready for the interesting workflows. Make a QR code now, or see what each plan includes.

#ai agents#mcp#openai#agentic web#automation