Can ChatGPT Fill In Your Contact Form? What We Saw When We Tested (2026)
Not in our test. On 25 September 2026 we asked ChatGPT, using its normal browsing, to fill in the quote form on our own website. It read the page, but it could not type into the form or press any buttons. An AI agent working inside Chrome was a different story. It could fill in the same form, and it could also see a hidden spam trap that people never see. That trap is the part that should worry you, because on most websites it quietly throws the enquiry away.
We have not yet tested ChatGPT’s agent mode, the version that operates a browser for you. It may behave differently, and we will update this article when we have tested it ourselves.
Two kinds of AI visitor
Most advice about “AI and your website” treats AI as one thing. Our testing showed two very different visitors.
The reading AI. This is ChatGPT search, or ChatGPT browsing a page because someone asked it a question. It fetches your page, pulls out the text, and uses it to write an answer. It reads. It does not click.
The acting agent. This is an AI that works inside a real browser and can do things on the page for the person who sent it: fill in fields, run a search, get a form ready to send. In our test, this was an agent working through WebMCP, a new way for a website to describe its forms to agents in Chrome. If you want the technical side, our WebMCP guide covers how it works and what we built.
The two need different things from your website. Work that helps one can do nothing at all for the other. So before you spend money on “making your site AI ready”, it helps to know which visitor you are getting ready for.
What ChatGPT could and could not do on our site
Here is what happened when we asked ChatGPT to check a domain name on our domain checker and to fill in our quote request form without sending it.
It reached both pages. ChatGPT’s fetcher loaded our live pages and read them. That is the first step, and it is worth confirming for your own site rather than assuming.
It could not use either one. In its own words: “the available web interface does not provide a way to enter values into JWD’s interactive form controls”. It could not run the domain check, and it could not fill in the quote form.
It did not make anything up. It refused to invent a domain result it had not actually seen. That is good behaviour, and worth knowing if you worry about AI quoting false facts about your business.
It saw only part of the form. When ChatGPT described our quote form back to us, it listed:
- Your name
- Phone / WhatsApp
- “two select fields”
- Rough budget (optional)
- The Send request button
It said itself that it could not see the labels or the options in the two dropdowns. It left out the message box completely. It did not see the hidden spam trap field. And it showed no sign of noticing the WebMCP information we had added to the form. It is not a WebMCP client, so that work did nothing for it.
Why it could not run our domain checker. The tool behind the domain checker only accepts form submissions, not a plain web address, and it sits in a folder we ask crawlers to stay out of. A reading AI fetches addresses. It does not submit forms. So even though the tool is public, ChatGPT’s browsing had no way in. If you want a reading AI to use a tool on your site, it has to work from a plain link.
What an acting agent could do
We then tested the same forms in Chrome with WebMCP switched on. Here we played the agent ourselves, calling the form’s tool through Chrome’s own WebMCP interface, the way an AI agent in the browser would.
The domain checker worked from start to finish. The agent asked for a domain, the tool ran the lookup, and the result came back to the agent. The page showed the same answer a person would see.
The quote form filled in, then waited. The agent filled in the fields. The browser then reported that an agent had used the form. And then nothing was sent. The form stayed waiting for a person to look it over and press Send. That is on purpose. We set the domain checker to run on its own, because a lookup harms nobody. We set the quote form to wait, because an enquiry should come from a person who means it.
We could tell it was an agent. When an agent fills in our quote form, a hidden marker is added to the enquiry. If that enquiry is sent, we know an agent helped prepare it. Nothing in that marker blocks the enquiry. It just tells us.
Since then, WebMCP loads on every page of our site, not only on the two form pages. On most pages it offers read-only tools, such as our package list. The only tool that prepares an enquiry is still the quote form, and it still waits for a person.
Reading AI vs acting agent: what each could do on our site
This is what we observed on our own site, in our tests on 25 September 2026.
| What we asked for | Reading AI (ChatGPT normal browsing) | Acting agent (WebMCP in Chrome) |
|---|---|---|
| Read the page text | Yes | Yes |
| See the dropdown labels and options | No, it said so | Yes, as a list of allowed choices |
| See the message box | No, it was missing from its list | Yes |
| See the hidden spam trap field | No | Yes, as an ordinary input |
| Run the domain checker | No | Yes, the result came back |
| Fill in the quote form | No | Yes |
| Send the quote form | No | No, it waited for a person, as we designed it |
| Use the WebMCP information on the form | No | Yes |
The honeypot problem
Many contact forms use a “honeypot” to stop spam. It is an extra field hidden from people. A person never sees it, so they leave it empty. A spam bot fills in every field it finds, so it fills that one too. When the honeypot has something in it, the website treats the message as spam and throws it away, usually without telling anyone.
Here is what we saw. In Chrome with WebMCP, our hidden honeypot field showed up to the agent as an ordinary input, right next to name and email. When our test agent put a value in it, the form accepted it.
Please read this part carefully, because it is easy to overstate:
- What we observed: an agent can see the hidden field as a normal input, and nothing stops it from filling it in.
- What we did not observe: a real, commercial AI agent actually filling it in. We have no proof that real agents will do this, and we have not tested how each agent treats a field it is told to leave empty.
- Why it still matters: on a typical website, a filled honeypot silently discards the lead. Nobody gets an error. The customer thinks they have sent an enquiry. You never see it. Neither of you knows a lead was lost.
That is a quiet way to lose business, and it is the kind of thing nobody notices until enquiries dry up.
What we did about it on our own form. We labelled the hidden field “Leave this empty. It must never be filled in.” so an agent is told plainly what to do. Then, as a safety net, we clear that field the moment the browser reports that an agent has used the form, and we add the agent marker. A spam bot does not trigger that browser event, so the spam protection still works against bots, and a genuine enquiry prepared by an agent is not thrown away.
How to make a form safe for people and agents
You do not need to understand the code to ask the right questions. Here is what we would check on any business enquiry form.
- Give every field a clear, visible label. ChatGPT could not read our dropdown labels. If an AI cannot tell what a field is for, it cannot help a customer fill it in correctly.
- Make sure the message box is easy to find. It is often the most important field, and it was the one ChatGPT left out.
- Check what your spam protection does with a filled honeypot. If it silently drops the message, that is a risk once agents start using your form. Ask your developer what happens, and whether the hidden field tells an agent to leave it empty.
- Never let an agent send an enquiry on its own. A lookup tool can run automatically. A form that reaches your inbox, books a slot or takes money should wait for a person to press the button.
- Put useful public tools behind a plain link as well. If you want ChatGPT’s browsing to use a tool, such as a price lookup or an availability check, it needs a normal address it can fetch.
- Mark enquiries that an agent helped with. You will want to know how much of your work arrives this way, and you cannot learn that later if you never recorded it.
Our agent-ready website checklist covers forms (checks 8 and 9) alongside the rest of what AI search and agents need from a site.
Should you bother yet?
Honestly, it depends on where your enquiries come from.
The reading-AI side matters now. ChatGPT read our pages in our test, and what it can read is what it can tell people about you. Clear pages, plain labels and true facts help with that today.
The acting-agent side is early. WebMCP is a draft from a W3C community group, not a finished web standard. Chrome is testing it through an origin trial, a time-limited test that websites sign up for. Chrome’s published plan for WebMCP lists that trial as running from Chrome 149 to Chrome 156 (we checked on 1 October 2026), and our own trial registration expires on 17 November 2026. We do not know yet what Chrome will do after the trial. It could become permanent, change, or be dropped.
So our advice is simple. Fix the things that help people and every kind of AI at once: labels, a findable message box, and spam protection that does not silently eat real enquiries. Those are worth doing whatever happens to WebMCP. Add the agent-specific parts when you build or rebuild a form anyway, rather than as a rush job.
If you are planning a new website, agent-ready forms can be part of the once-off build, quoted per project like everything else. You can see how we approach it on our AI search visibility and agent-ready websites page.
Related reading: how PageSpeed Insights scores this, in PageSpeed Agentic Browsing explained, and how to see which enquiries an AI actually sent you, in measuring leads from ChatGPT.
Frequently Asked Questions
Can ChatGPT fill in a contact form on my website?
In our test on 25 September 2026, ChatGPT’s normal browsing could not. It read our pages but said it had no way to enter values into the form. We have not yet tested ChatGPT’s agent mode, which works in a browser and may behave differently.
What is the difference between a reading AI and an acting agent?
A reading AI, such as ChatGPT search, fetches your page and uses the text to answer a question. An acting agent works in a browser and can fill in fields and run tools on the page for the person who sent it.
Can AI agents see hidden honeypot fields?
In our Chrome test with WebMCP, yes. The hidden field appeared to the agent as an ordinary input, and a value we supplied was accepted. That is not proof real agents will fill it, but nothing stops them, and on many sites a filled honeypot silently discards the enquiry.
Will an AI agent send enquiries without the customer knowing?
On our quote form it cannot. The agent fills in the fields, and the form then waits for a person to press Send. Whether another website’s form waits depends on how that form was built.
Do I need WebMCP on my website right now?
Not urgently. It is still in a Chrome trial and its future is not settled. Clear labels, a visible message box and safe spam protection help people and every AI today, so start there.
Want your forms checked?
If you would like to know how your enquiry form behaves for people, reading AIs and agents, have a look at our AI search visibility and agent-ready websites service, or ask us for a quote.