Somebody on X posted screenshots from Microsoft’s latest agent preview last week, and buried under the Copilot branding was what looked like yet another cloud-hosted browser automation tool. Same architecture as OpenClaw. Same approach as NemoClaw. Same remote-execution model that Google, Nvidia, and now apparently every company with a cloud platform thinks is the future of getting stuff done in a browser.

I have lost count of how many of these have shipped in the past three months.

Another entrant, same blueprint

Microsoft’s version reportedly uses Azure infrastructure to spin up cloud browser instances that execute tasks on your behalf. If that sounds familiar, it should be. This is the OpenClaw pattern wrapped in enterprise packaging. And Microsoft has real advantages here: massive Copilot distribution, deep Office integration, and the Azure muscle to run things at scale.

But distribution and scale do not fix an architectural problem that sits underneath all of it. A cloud browser instance running on Azure has zero knowledge of your actual browser state. No cookies from your logged-in tabs. No session persistence from the SaaS tools you authenticated into this morning. No context about the page you are currently staring at.

Headless Chrome still does not know your Gmail password

NemoClaw at GTC. Google’s browser agent push. Multiple Y Combinator startups building variations on the theme. And now Microsoft. Every one of these projects treats browser automation as a cloud orchestration problem, and every one crashes into the same wall: cloud browsers start from zero.

A fresh headless Chrome instance on a Microsoft server cannot access your company’s internal tools behind SSO. It will trigger bot detection on half the sites you visit daily because those sites were specifically engineered to reject exactly this kind of automated access. So before the agent can even attempt whatever task you asked it to do, it first has to solve authentication across every service involved, and authentication on the modern web is a hostile landscape of MFA prompts, rotating session tokens, and CAPTCHAs that exist to stop cloud-hosted bots from doing exactly what these agents promise to do.

But more companies entering this race does not make the wall shorter.

Same wall, bigger ladder

More cloud infrastructure does not make the authentication problem disappear. It just runs headless Chrome on fancier servers.

Your browser is not on Azure

The Chrome profile you are using right now contains active authenticated sessions for dozens of services. You do not think about it because the whole point of persistent sessions is that you authenticated once and moved on with your life, but that accumulated state represents a massive amount of context that no cloud agent can replicate without asking you to hand over your credentials or re-authenticate for every damn task.

And beyond the authentication gap, there is a speed difference these cloud demos carefully avoid showing. A cloud browser agent screenshots the page, sends the image to a model, receives instructions back, executes a click, screenshots again. Each cycle adds seconds of latency. A local agent reads the DOM directly, which takes milliseconds, because there is no network round trip between the agent and the page you are looking at.

Dassi runs as a Chrome extension inside your actual browser, which means it inherits all of that session state automatically. When you ask it to draft an email reply or pull data from your CRM, it reads the real page with your real login. No headless Chrome on somebody else’s server. And because Dassi supports multiple LLM providers with BYOK, you are not locked into Microsoft’s model choices either — worth mentioning given that platform lock-in already bit OpenClaw users this month.

Counting clones

OpenClaw, NemoClaw, Google’s agent tools, at least a dozen funded startups, and now Microsoft. All building cloud-hosted browser agents. And the combined investment probably runs into billions. But not a single one can fill out a form on a site where you are already logged in without either stealing your cookies or making you log in again inside their sandbox.

The number of companies trying this approach keeps growing. But the fundamental limitation stays exactly the same. At some point somebody at one of these companies is going to look at the authentication problem, look at the bot detection problem, look at the latency overhead of screenshotting pages and round-tripping instructions to a remote model, and ask whether maybe the agent should just run where the browser already is.

That meeting has not happened yet. Or if it has, nobody acted on it.