Claude in Chrome: your browser just hired an assistant
Anthropic’s research preview puts Claude in a Chrome sidebar that can see your page and, with your permission, click, type, and scroll for you. What it actually does, the permission model, why the rollout is tiny, and where it is heading.
Watch the companion reel ↗ Claude in Chrome: your browser just hired an assistant
Explain it like I’m five
Imagine you hire a helper who sits next to you at your desk and watches your screen. You say “book me the cheapest flight,” and they start clicking through airline sites for you — but they stop and ask “okay to click this?” before every single click. That is Claude in Chrome: a very capable intern living in your browser, with a strict ask-first rule.
The big idea is simple. Until now, AI assistants could only talk about the web. Now one can touch it: see what you see, press the buttons, fill in the boxes. Everything else in this guide is about what that unlocks — and why Anthropic is being unusually careful about it.
What it is
Claude in Chrome is a research-preview Chrome extension from Anthropic. Claude lives in a sidebar next to your tabs: it can see the page you are looking at and, with your say-so, click buttons, fill forms, type, and scroll.
Anthropic announced it in August 2025 as a deliberately small pilot: 1,000 trusted testers on the company’s Max plan (the $100–$200/month tier), plus a public waitlist at claude.ai/chrome for everyone else. The framing was explicit — this is a research preview to work out the safety problems before any wider release, not a finished product launch.
Claude in Chrome works inside your existing Chrome: your tabs, your bookmarks, your logged-in sites. That is what makes it powerful and what makes it risky — the agent operates where your real accounts live. (Anthropic later built a separate, isolated browser into Claude Cowork; more on that below.)
Source: StartupNews — research preview announcement ↗
What it actually does
The shift that matters: this is not a chatbot that answers questions about the web. It does things on the web — multi-step work, across pages, in your browser.
The examples Anthropic itself pointed to at launch: managing calendars, scheduling meetings, drafting email responses, and testing website features by clicking through them the way a user would. In practice, that covers the boring middle of knowledge work — the stuff that is ten tabs, three forms, and forty clicks.
The expense report. You forward Claude a pile of receipts and say “file these.” It opens your company’s expense portal, creates a new report, fills in each line item, attaches the receipts, and stops at the submit button to ask you to review. The thirty minutes of clicking becomes three minutes of reviewing.
Flight comparison. “Find me the cheapest nonstop Friday evening flight.” Claude opens five airline tabs, applies the same filters on each, and brings back a comparison — work that is genuinely miserable to do by hand and trivially parallel for an agent.
Website testing. A developer asks Claude to click through a new signup flow like a first-time user and report where it breaks. The agent is the QA intern, running the exact path a human would.
The pattern: if a task is “open pages, read, click, repeat,” it is agent-shaped work.
Source: SiliconANGLE — Anthropic’s stated early use cases ↗The permission rule: nothing happens without you
The single most important design decision: every action asks first. Claude does not freelance in your browser — it proposes, you approve, it clicks.
- Per-action consent. Filling forms, clicking buttons, managing emails — each step happens with your consent, and you can watch everything it does.
- Site-by-site access. You grant the extension access where you want it, not a blank check across the whole web.
- Sensitive stuff stays fenced off. Banking, passwords, and logins are not handed over by default; the agent works with what you explicitly allow.
A browser agent without strict permissions would be a skeleton key to your digital life — email, bank, identity, everything. The ask-first model is the difference between a helpful intern and a liability. It is also why some people find agents slower than doing the task themselves: every permission popup is a context switch back to you.
Why the rollout is tiny
One thousand testers is not a launch — it is a laboratory. Anthropic kept the preview small on purpose, and the reason has a name: prompt injection.
A browser agent reads web pages to do its job. But web pages can contain instructions — hidden text, disguised as content, telling the agent to do something you never asked for. A shady page could, in principle, trick Claude into exfiltrating data or taking actions on your accounts. This is the central unsolved safety problem for every browser agent, not just Anthropic’s, and it is why the company framed the preview as security research first and product second.
Anthropic’s caution contrasts with competitors who shipped browser agents to broad audiences faster. Smaller blast radius means slower learning — but when the failure mode is “agent does something irreversible in your bank account,” slow is a feature.
Where it is heading: Cowork’s own browser
The extension was step one. Step two is a browser that was built for agents from the start.
In 2026, Anthropic gave Claude Cowork — its desktop agent for longer tasks — a built-in browser that opens in a side panel. The key difference from the Chrome extension: this browser is separate. It never sees your tabs, your history, or your passwords. Logins are brought over site by site, only where you choose, and banking and single-sign-on stay fenced off. If you prefer the old way, you can switch back to Claude in Chrome from settings.
The rollout started on Enterprise plans and moved to Pro, Max, and Team. The direction is clear: agents get their own sandboxed browser for the web’s public rooms, and your personal browser stays yours.
Hands-off research. You ask Cowork to research a topic across dozens of sources. Its built-in browser opens pages in the side panel, reads them, and cites them — while your own Chrome, with your logged-in email and bank tabs, is never in the room. Separation is the safety feature.
FAQ
It remains a limited research preview: 1,000 Max-plan testers plus a waitlist at claude.ai/chrome. If you are on Pro, Max, or Team, check whether Cowork’s built-in browser has rolled out to your account — that is the newer, more widely available path to agentic browsing.
Not by default. Access is granted site by site, every action asks first, and sensitive categories stay fenced off unless you explicitly allow them. Cowork’s separate browser goes further: it never touches your tabs or stored logins at all.
Claude in Chrome is an extension inside your Chrome: powerful, personal, permission-gated. Cowork’s browser is a separate, sandboxed browser for the agent’s own use: safer by isolation, but it starts with none of your logins. You can switch between them in settings.
An agent that reads web pages can be fooled by web pages. Attackers hide instructions in page content — invisible text, misleading copy — that the agent may treat as commands from you. Until agents reliably distinguish “content to read” from “instructions to follow,” every browser agent ships with guardrails, and Anthropic’s answer so far is: tiny rollout, ask-first permissions, and a sandboxed browser.
The Chrome extension preview was limited to Max-plan subscribers ($100–$200/month). Cowork’s built-in browser rides along with existing plans as it rolls out — longer agentic tasks consume more of your plan’s usage limits than quick questions.
Takeaways
- Talking became doing. Claude in Chrome moves the assistant from answering questions about the web to performing multi-step work inside it — the defining shift from chatbot to agent.
- Ask-first is the whole safety model. Per-action consent, site-by-site access, and fenced-off banking are what make a browser agent trustworthy — and the popups are also its biggest usability cost.
- Prompt injection is the open problem. Hidden instructions on web pages can trick agents, which is why Anthropic ran this as a 1,000-person security experiment before any real launch.
- Isolation is the future. Cowork’s separate built-in browser — no access to your tabs, history, or passwords — shows where agentic browsing is heading: the agent gets its own room, not the keys to yours.
- Agent-shaped work is “open, read, click, repeat.” Expense reports, flight comparisons, signup-flow testing — if the task is tabs and forms, an agent is the right tool.
Sources
Every factual claim in this guide — the August 2025 research preview, the 1,000-tester Max-plan pilot and waitlist, the per-action consent model, the stated use cases, the prompt-injection caution, and Cowork’s built-in browser rollout — comes from the press coverage of Anthropic’s announcements linked below, read on October 7, 2026. The analogies, use cases, and explanations are our own.
- SiliconANGLE — Anthropic pilots experimental Claude AI plugin that can take control of Chrome (pilot scope, waitlist, early use cases) ↗
- StartupNews — Anthropic launches a Claude AI agent that lives in Chrome (research preview framing) ↗
- VentureBeat — Claude for Chrome in limited beta (prompt-injection concern) ↗
- The Eastleigh Voice — Claude browses the web for you (per-step user consent) ↗
- Gizmodo — Cowork’s built-in browser (separate browser, rollout, settings switch) ↗
Companion reel: this guide will be linked from @theclaudecraft’s “Claude in Chrome” reel once it posts.