AI Events
Hark's New Agent Can Shop, Book, and Recruit for You. It Never Says How It Proves You Said Yes.
On August 5, Brett Adcock's startup Hark previewed Handoff, a browser-use agent that orders food, books flights, and messages job candidates on real websites that were never built for agents. Every writeup covered what it can do. None of them covered how anyone would prove it was allowed to.
What happened
On August 5, 2026, Hark — the AI hardware startup founded by Brett Adcock, who also built Figure AI and Archer Aviation — released a technical preview of Handoff, its first shipped product. Handoff is a browser-use agent: it looks at a website's visual and structural layout, then clicks, types, and navigates the same way a person would — which matters because most of the sites it operates on have no official API for agents to call instead.
Hark's own announcement demoed Handoff building a custom flower bouquet from vague instructions, ordering through DoorDash and Uber Eats, comparing and booking flights across United, Delta, and American, and shopping on Target and Walmart. A separate demo showed it working LinkedIn — researching candidates and sending recruiting messages on a user's behalf. Founder Brett Adcock described the goal plainly: “we're creating the world's most capable, personal intelligence — a system to take on tasks and create space to focus on what we choose.”
The launch lands on the back of real money: Hark closed a $700 million Series A at a $6 billion valuation in May, backed by Parkway Venture Capital, Nvidia, AMD, Brookfield, Intel Capital, Qualcomm, and Salesforce Ventures. Hark says the reason it started with a browser agent rather than hardware is that 74.9% of computer use happens inside a browser. A public launch is planned for later this summer; a waitlist is open now.
A question every outlet skipped
Hark also claims Handoff posted the top-ever score on the OM2W web-use benchmark, ahead of models from OpenAI, Anthropic, and Google, at a fraction of the per-token cost. Those are Hark's own numbers from its own preview, not an independently verified result, and coverage of the benchmark claim varied outlet to outlet — which is itself worth naming rather than repeating as settled fact.
What every outlet agreed on, whether they flagged it or not, is what was absent. Handoff is being demoed holding a credit card across four retailers, a checking-account-linked food order, and a LinkedIn account sending messages to real people — and none of the coverage, including Hark's own announcement, describes how the system proves a given action was actually authorized by the account holder, or how a retailer, airline, or candidate on the other end of that session is supposed to tell Handoff apart from the person whose browser it's driving. One reviewer put the gap directly: “Handing an agent a credit card and a shipping address to shop across four retailers is a different level of delegation than asking a chatbot to summarize a PDF.” The same reporting notes Hark has announced no explicit guarantees about transaction failures or liability. A company spokesperson's only public comment on the subject was that security and privacy are “a primary focus” of a preview that isn't final — a placeholder, not a mechanism.
Why this isn't a Hark-specific problem
Handoff is a sharp example of a gap that's industry-wide, not a flaw unique to one preview. A DataTribe report published July 27, 2026 found that roughly a quarter of deployed agents today can spawn sub-agents and hand off live credentials with no verification, scoping, or audit trail — the sub-agent simply inherits whatever access its parent held, almost always more than the sub-task needs. The same report found that adding least-privilege access controls cut incident rates from over two-thirds of deployments down to under 20%, which tells you the exposure is fixable, not fundamental. It just isn't fixed by default, and it wasn't addressed in Hark's own announcement of a product built specifically to hold credentials and act with them.
Browser-use agents make the gap harder to ignore than API-based ones, for a structural reason: an API call can be scoped, logged, and rate-limited by the platform on the other end before it ever executes. A browser session that clicks and types like a human looks, to Target or United or LinkedIn, exactly like a human is sitting there — because that's the entire design goal. The retailer has no native way to ask “which agent is this, and did its owner actually authorize this specific purchase,” because the session gives it nothing to check that against.
Where AAIN and SKOOR fit — honestly
This is not a story where SKOOR would have caught a breach; nothing in Handoff's preview has misbehaved. It's a story about a widening gap between what agents are now allowed to do — spend money, message real people, act on accounts — and what the surrounding infrastructure requires them to prove before doing it. That gap is exactly the one AAIN and SKOOR exist to close, and the fit here is direct rather than stretched.
The AAIN — a permanent, independently assigned identifier — is the missing piece a retailer or airline would need to answer “which agent is this” for a browser session that otherwise looks indistinguishable from a human. It can't be self-asserted by the agent (a bearer credential proves nothing, as agent-security research keeps demonstrating this year); it has to be resolvable by the party on the receiving end of the transaction.
Constraint adherence
Once an agent has an identity, whether it stays inside the specific spending limits, retailers, or message types it was authorized for becomes a measurable, scoreable pattern — not a one-time permission grant nobody checks again.
Intent fidelity
"Order dinner" and "book the cheapest flight" are underspecified by design — that's the appeal of a browser agent. Whether the agent's interpretation of a vague instruction matched what the user actually meant is exactly the drift this factor is built to catch.
Payment history
An agent holding a credit card across four retailers is a payment actor. A durable record of how it has handled money in the past is the difference between a retailer trusting a specific agent's checkout and trusting any browser session that shows up looking human.
SKOOR scores over 150,900 agents today, continuously, across ten factors like these, with every score backed by a factor breakdown anyone can inspect. That doesn't make a browser-use agent safe by itself — identity and scoring are infrastructure, not a guarantee. But infrastructure is precisely what today's coverage of Handoff shows is still missing: a way for the businesses on the other end of these sessions to ask the question none of them can currently ask.
What this means if you run a business
Agents like Handoff are going to show up in your order queue, your booking system, or your inbox this year, whether or not you've opted in — a browser-use agent looks like a customer, not like traffic you can filter. Before that happens, it's worth asking your own team three questions Hark's launch didn't answer for its users:
- Can you tell an agent session from a human one? If not, every policy you have written for human customers silently applies, or doesn't apply, to agents by accident.
- If an agent places an order or books an appointment on your platform, do you have any record of which agent it was? A name typed into a form isn't identity. A resolvable identifier is.
- Would you know if the same agent came back and behaved differently than last time? That's a continuously scored track record, not a one-time check at signup.
None of that requires blocking agents — blocking them is a losing strategy against agents literally designed to look human. It requires infrastructure that gives you a durable identity to check and a score that reflects how that identity has behaved everywhere else, not just in the session in front of you right now.
Know which agents you can trust
Look up any agent's SKOOR and see the full factor breakdown — including whether it holds the kind of history a payment or booking should be able to check.
Check a SKOOR