Web Design & Dev · News

July 2026 — Web Design & Dev news.

July 2026

What changed, as it happens.

Tracked daily from primary sources. The items below are what we're watching for clients right now.

  1. CSS · Layout

    CSS border-shape takes shaped elements past what border-radius can do

    CSS-Tricks published an explainer on border-shape, a CSS Borders Module Level 4 property that accepts the same values as clip-path — including the newer shape() function — but shapes the whole element rather than clipping it. That distinction is the point: borders, box-shadows, and outlines follow the shaped path instead of being cut off at it, which makes putting a real border on a non-rectangular CSS shape straightforward for the first time. Support is Chrome-only as of July 2026, so treat it as something to explore rather than ship.Source: CSS-Tricks →

    Our take: Chrome-only means explore, don't ship. For stores it's eventual relief from the SVG-mask gymnastics behind badge shapes and promo callouts, a progressive-enhancement candidate for late 2026, not a today tool.

    Read our full take →
  2. AI Tooling · Design Systems

    NN/G floats a “UX.md” — machine-readable context for AI-generated design

    Nielsen Norman Group argues UX work should shift toward curating machine-readable context that AI tools consume when they generate design, rather than producing human-only deliverables like personas and reports. The anchor is real: Google Labs open-sourced DESIGN.md in April 2026, a file that lives alongside a product’s code and pairs machine-readable values — colors, type sizes, spacing — with human-readable guidance so a tool knows what a color is actually for. “UX.md” itself is NN/G’s thought experiment, not a standard anyone implements yet. Worth reading as a direction, not a checklist.Source: Nielsen Norman Group →

    Our take: The direction is real even if UX.md isn't a standard yet: machine-readable design context is how AI-generated pages stay on-brand. We keep exactly that, tokens plus intent, in this site's repo; it's why AI-assisted edits don't drift the palette.

    Read our full take →
  3. UX · Forms

    NN/G on dropdowns: use them sparingly, and switch to a combobox past ~15 options

    NN/G recommends moving to a combobox once a list exceeds roughly 15 options, and notes the major design systems all put the small-list cutoff low — the U.S. Web Design System says use radio buttons under 7 items, Material Design draws the line at 6, IBM’s Carbon at 3. It cites GOV.UK research documenting how dropdowns fail users with disabilities: trouble closing them, typing into them, confusing focused items with selected ones, and not realizing more options exist below the fold. GOV.UK’s own position is that dropdowns should be a last resort in public-facing services. Relevant to any store with variant pickers, filter menus, or a long country/state field at checkout.Source: Nielsen Norman Group →

    Our take: Count the options in your variant pickers and the checkout country field. Past roughly 15, a searchable combobox beats a dropdown — and checkout is where those seconds cost real money. The accessibility failures GOV.UK documents are lawsuit surface, too.

    Read our full take →
  4. Agentic Web · Security

    Chrome warns the WebMCP tools you expose to agents can be used to hijack them

    Chrome’s developer docs for WebMCP (still in origin trial) describe two attack vectors — malicious tool manifests and “contaminated output,” where user-generated content like reviews carries hidden instructions an agent then follows — and specify mitigations for site owners: an untrustedContentHint flag, a readOnlyHint, exposedTo origin restriction, and character-budget caps on tool descriptions and outputs. If you wire up WebMCP tools, treat any UGC-derived text as untrusted before an agent acts on it.Source: Search Engine Journal →

    Our take: If you expose WebMCP tools, treat your own reviews and UGC as hostile input — contaminated output is prompt injection through content you host. Chrome's mitigation flags are the checklist; use all of them.

    Read our full take →
  5. UX · AI Chatbots

    Five qualities that make a site’s AI chatbot trustworthy

    NN/G names five design dimensions for site-specific AI chatbots: handoff willingness (respecting a user who wants a human), flexibility within defined guardrails, proactivity in suggesting next steps, emotional responsiveness, and transparency about the bot’s identity, capabilities, and reasoning. That last one is becoming a legal requirement rather than a courtesy — the article notes EU rules mandating AI-identity disclosure take effect in August 2026. If you’re putting an assistant on a storefront, the handoff path and the disclosure are the two to get right first.Source: Nielsen Norman Group →

    Our take: Adding a storefront assistant? Get two things right before any clever parts: a real path to a human, and clear disclosure that it's a bot. The EU makes the second one law in August, so build it as the default, not the retrofit.

    Read our full take →
  6. Agentic Web · Browsers

    Safari/WebKit ships an MCP server for AI-assisted web debugging

    Apple’s WebKit released a Model Context Protocol server for Safari that lets AI agents connect to the browser to collect network and DOM data, aimed at debugging accessibility, compatibility, and performance issues including Core Web Vitals. Another mainstream browser wiring itself for agent access.Source: Search Engine Journal →

    Our take: Every major browser wiring in agent access is the trend line. The debugging use is real today: Core Web Vitals and accessibility diagnosis through an agent beats clicking through DevTools panels one screenshot at a time.

    Read our full take →
All Web Design & Dev news

Custom ecommerce software, AI apps, and SEO — the work other agencies quote around, built in-house.

20+ years of BigCommerce engineering, now AI-augmented. Tell us your store, your stack, and your deadline — we quote fixed scope on the first call.