Five things you shouldn't do with WebBrain
We have been deep in the serious stuff lately: planner benchmarks, tool-call scores, local model shootouts, and other charts that make everyone feel like they should be drinking water and using a second monitor.
So this is a short pause for the video below: Five Things You Shouldn't Do with WebBrain! It is a comedy warning label for a very real truth. WebBrain can read pages, compare information, click buttons, fill forms, and help you move around the web faster. That power is useful. It is also not a permission slip.
Before anyone opens a new tab with suspicious confidence: this is not legal advice, not evasion advice, and definitely not reverse psychology. If the plan depends on unauthorized access, deception, spam, bypassing rules, or pretending the AI did it instead of you, the answer is no.
1. The terms-of-service speedrun
Could a browser agent help you move through a site very quickly? Yes. Should you use it to turn one normal user account into a tiny unlicensed data center, mass-create accounts, ignore rate limits, or treat a website's front end like a secret free API? No.
The useful version is boring: collect information you are allowed to collect, at a human-respectful pace, for a purpose you can explain without lowering your voice.
The shady version is the one where your defense is, "Technically, the button was visible." That is not a defense. That is the opening line of an uncomfortable email from a trust and safety team.
2. The spam cannon with a blazer
WebBrain can help draft emails, summarize conversations, and fill forms. That does not mean it should become a polite-looking machine for mass DMs, fake reviews, astroturf comments, referral stuffing, or "personalized outreach" that is only personalized because the first name field worked.
Use it to write better messages. Do not use it to make the internet worse at scale. Nobody wants to receive 400 variations of "quick question" from a robot wearing a LinkedIn badge.
3. The private-tab treasure hunt
If you are logged into something, WebBrain can often help you understand what is on the page. That is great when it is your dashboard, your inbox, your bill, your admin panel, or a document you are allowed to handle.
It is not great when the tab belongs to someone else, the document was not meant for you, or the whole plan starts with, "My coworker left their laptop open." A browser agent does not launder access. If you were not allowed to look, you are not allowed to ask an AI to look with extra steps.
4. The checkout supervillain arc
Comparison shopping? Fine. Finding your own order status? Fine. Filling a normal form you were already going to submit? Fine.
Trying to abuse coupons, fake refunds, fake reviews, returns, chargebacks, loyalty programs, seller dashboards, marketplace disputes, or payment flows? No. That is not "automation." That is a quick route from "fun demo" to "why is my account locked?"
WebBrain is much better as a calm assistant than as a tiny accomplice in a trench coat. And yes, the trench coat is also against the terms.
5. The "the AI clicked it" alibi
This is the big one. WebBrain can help you click, type, navigate, and submit. But the browser is still yours. The account is still yours. The action is still yours.
If you would not click the button yourself, do not ask an agent to click it for you. If you would be embarrassed to explain the task out loud, do not wrap it in automation and call it research. If the only reason it feels okay is that the AI is doing the awkward part, that is not a loophole. That is the warning light.
The actual rule
Use WebBrain for the good boring stuff: reading pages, comparing options, checking your own accounts, drafting your own messages, organizing research, and automating workflows where you have permission to be.
Do not use it for unauthorized access, fraud, spam, harassment, impersonation, platform abuse, or anything where your best argument is "but the model agreed."
And now, with that responsible sentence safely on the record, we can go back to benchmarking models and pretending the real drama is whether a planner chooses get_accessibility_tree or read_page first.