Anthropic has moved Claude in Chrome from pilot to general availability for every paid Claude plan. The 26 August product announcement makes the browser extension a mainstream part of Claude’s workflow rather than a limited experiment: users can hand Claude a task, let it work across tabs, and continue the conversation in the web, mobile or desktop apps. The most consequential change is that Claude can now take browser actions autonomously when its safeguards judge those actions safe, rather than asking for approval at every step.

That distinction matters because browser work is where AI assistance becomes operational. Reading a dashboard, comparing records across tabs, filling in a form or moving through a vendor portal all require the model to interact with information that changes from moment to moment. Anthropic says Claude in Chrome can view the current page and perform actions including reading and typing text, clicking links, navigating and filling forms using a person’s existing logins. In practical terms, that can turn a multi-tab research or administration task into a delegated workflow, with the user still setting the objective.

General availability comes with a security emphasis

Anthropic’s announcement gives unusual prominence to the risk model behind browser automation. A browser agent processes material it did not create: web pages, email messages, form fields and dashboards can all carry hidden instructions intended to divert the agent. That is the core prompt-injection problem. A request to summarise an inbox, for example, should not become an instruction to expose unrelated mail merely because a malicious message contains text aimed at the model.

The company describes a layered approach. Claude is trained against a growing library of attacks sourced from internal automated attackers, external red teams and real-world monitoring. Probes inspect the tool results that deliver page content to Claude and can warn the model when they identify a likely injection attempt. Finally, a classifier assesses an action before it runs, comparing it with the user’s original request. An action outside that intent is meant to be blocked. Anthropic says users may switch off automatic approval in settings if they would rather keep approving actions themselves.

This is not a claim that browser automation is risk-free. It is a specific attempt to make autonomy conditional. The product’s architecture separates receiving untrusted web content, reasoning over that content and executing a consequential action. That separation is important for organisations evaluating agentic tools: the useful question is not simply whether an assistant can click, but which checks sit between a potentially manipulated page and a click that changes something.

What paid Claude users can do now

The general release is available on every paid Claude plan, according to Anthropic. Enterprise administrators can manage the extension in Organisation Settings and restrict it to approved domains, a control that should matter wherever an organisation needs to limit which web systems an assistant can access. The extension is installed through the Chrome Web Store. Anthropic also notes a clear boundary: Claude in Chrome does not yet run in other Chromium browsers or on mobile.

Another boundary is local work. The announcement says users still need the Claude desktop app to work with files on their computer or with other applications. That leaves Claude in Chrome focused on the authenticated, browser-based part of a task rather than presenting it as a complete replacement for desktop automation. It also gives teams a simpler way to distinguish a web-access capability from a broader endpoint-access capability when setting policies and training users.

For individual users, the appeal is continuity. A task begun in the browser does not need to remain there; the underlying Claude conversation can carry on across the company’s apps. For teams, the useful pattern may be more disciplined: define the intended outcome, limit the set of domains, monitor where sensitive content is involved and decide whether automatic approvals are appropriate for that workflow. The release supports those choices without making them for every customer.

A shift from assisted browsing to governed delegation

The pilot phase established that Claude could operate in a browser. General availability changes the product conversation to one about repeatable use. A model that pauses for every action can be helpful but cumbersome in long workflows. A model allowed to proceed within carefully bounded intent can take on more of the routine sequence, provided users understand the trade-off and retain the ability to intervene.

Anthropic’s published evaluation framing also gives security and procurement teams material to examine. The company says it tested browser-use safeguards and reports that, in its Cowork harness, no attack succeeded against several current Claude models even without the probes and classifiers. Those results should be read as vendor-reported evaluation evidence, not as a guarantee for every site or task. Real browser environments vary widely, and organisations should still test the extension against their own high-risk workflows before expanding access.

The broader signal is that browser agents are becoming a normal product surface for paid AI assistants. Claude in Chrome’s release combines access to existing web tools with a set of stated limits, controls and defences. Users who want an assistant to do more than answer questions now have a way to delegate browser steps, while administrators gain domain restrictions and users retain a settings choice around automatic action approval. As this category grows, those implementation details will matter as much as the headline capability.

Anthropic published the announcement on 26 August 2026 and positions the release as a product update for Claude Cowork and Claude apps. The company’s own source is the basis for this report; availability, plan access and safeguards may evolve, so readers should check the product page and administration guidance before relying on the feature in a sensitive workflow.