Every number on this site comes from here.
These are our own measurements, not an independent study. This page says how many clicks and browsers they cover, which AI agents we ran, how the data was collected — and, just as important, where the method fails. When design partners run OneHuman on real traffic, their numbers will be added here with their permission.
2 / 397human clicks read as a program (0.5%)
2 / 824agent clicks read as a person (0.2%) — 600 of them generated, see below
88%of human clicks let through on the first click; the rest waited for more evidence
0.1–0.5 sfrom Claude in Chrome attaching to the session being marked, in 4 runs
Who and what was measured
| People | [N people — being confirmed], using their own computers and phones | |
|---|---|---|
| Browsers and devices | 22 distinct browser/device installations for the human clicks | 22 |
| Human clicks | Chrome with a mouse (179), Chrome with a trackpad (80), trackpad tap-to-click (10), fast mouse (10), Safari (37), Windows mouse (72), a person clicking inside an AI agent's side panel (8), a person working alongside Codex (1) | 397 |
| Not counted | 59 touch clicks from 2 phones. Touch has no pointer path, and today every touch click stays undecided — the rules decide what undecided gets. They are shown here so the total is honest. | 59 |
| Agent clicks, real products | AI agents driving Chrome through extensions (185), agent browsers built into desktop apps (29), Claude's desktop app browser (10) | 224 |
| Agent clicks, generated | Six variants of "human-like cursor" libraries, 100 paths each. These are simulations of bots trying to look human, not real browser events. | 600 |
Agent products run live against our demo bank: Claude in Chrome, the Claude desktop app, the Codex Chrome extension, the Codex built-in browser (two versions), Puppeteer and Playwright scripts. Not tested yet: Perplexity Comet, ChatGPT Atlas and agent mode, Browser Use cloud. Per-product results: agent scorecard.
How the data was collected
- People did the same 13 short tasks on a training page — open, read, click, type, download — in their own browser, with the input they normally use.
- Agents were given the same kind of tasks on the live demo bank, with the page script running exactly as it runs for a customer.
- Timing of detection comes from the page script's own timestamps, from the moment an agent attaches to an open tab.
- Collected in September 2026. Engine versions: assess-v7, kinematics kin-v16, model of 22 September 2026.
How it was evaluated
- Kept apart by device. The click model was tested with grouped five-fold cross-validation: every browser or device is tested by a model that never saw its clicks, so a good result cannot come from recognising the device.
- Undecided is a real answer. A click is let through on its own only when it is clearly a person's. Anything in between is undecided, never treated as human; your rules decide what undecided gets (often: ask for a passkey).
- Whole sessions too. Besides single clicks, 15 full recorded sessions were replayed through the engine; none got a wrong session decision. Fifteen is a small number, and we say so.
Where it fails
- A script written for one site. In our own red-team test, a script that fakes a human pointer and never reads the page passed as a person 16 times out of 16. The behaviour check alone cannot stop it; a passkey on critical actions does.
- Replaying a real person's movement. A recorded human pointer path, replayed by a program, passes the per-click check. The session layer and the passkey are the answer, not the click check.
- Touch input stays undecided: we have no reliable baseline yet for an agent using touch.
- Safari lets through fewer people on the first click (68% versus 84–100% elsewhere); they are asked for more evidence, not blocked.
- An agent that only looks — takes screenshots without acting — is seen as present in the browser, not as acting.
- Before the first protected request an agent that left no trace in the page is unknown. Rules that allow unknown will serve it.
- Signed agents (Web Bot Auth) were tested with a test key only; no public operator has been tested live.
- Scale. 397 clicks from a small group is not a population. The rate at which real customers would be misread is not established yet; that is what the design-partner trials measure.
Found something that gets through, or a number that does not add up? Write to security@onehuman.ai. We add it to this page.