What To Know
- The AI company is introducing a custom browser directly inside Claude Cowork while simultaneously expanding Claude in Chrome, giving its assistant increasingly powerful capabilities to navigate websites, enter information, click links, complete forms, and carry out multi-step online tasks.
- Within Claude Cowork, the company has introduced a dedicated browser that can automatically appear in a side panel when Claude determines that a task requires information from the web.
Anthropic is escalating the battle to control how people use the internet, rolling out browser technology that could make Google Chrome less essential for users of its Claude artificial intelligence platform. The AI company is introducing a custom browser directly inside Claude Cowork while simultaneously expanding Claude in Chrome, giving its assistant increasingly powerful capabilities to navigate websites, enter information, click links, complete forms, and carry out multi-step online tasks.

Image Credit: Thailand AI News
The development reflects a much bigger shift taking place across the AI industry. Chatbots are rapidly evolving from systems that simply answer questions into agents capable of taking action on behalf of users. this AI News report examines how Anthropic is moving directly into territory traditionally dominated by Google, while attempting to solve one of the most difficult problems facing autonomous AI: allowing an intelligent agent to roam the web without exposing users to unacceptable security risks.
Claude Gets a Browser of Its Own
Anthropic’s new approach means many Claude users will no longer need to give the AI access to their personal browser simply to perform routine searches.
Within Claude Cowork, the company has introduced a dedicated browser that can automatically appear in a side panel when Claude determines that a task requires information from the web. The browser is primarily designed for searching publicly available information and does not automatically inherit sensitive login credentials for services such as banking or email.
That separation could prove significant. Until now, Claude’s browser interaction depended heavily on Claude in Chrome, an extension that allows the AI to operate inside Google’s dominant browser environment.
Anthropic’s argument is straightforward: many AI tasks do not require access to a person’s browser at all. They simply require a browser.
The built-in Cowork browser is available for Enterprise customers and is being rolled out to Pro, Max, and Team subscribers. Users and administrators can still switch back to Claude in Chrome where appropriate.
Google Faces a New Kind of Browser Challenge
Chrome remains enormously powerful, accounting for close to 70% of global web traffic according to Statcounter figures cited in the supplied material. However, AI assistants are changing the way people discover and interact with online information.
Instead of opening a browser, searching Google, reviewing links, visiting several websites and manually completing tasks, users increasingly expect an AI system to handle much of that process.
That changes the competitive equation.
If Claude can search the web, interact with websites and complete digital workflows from a single interface, the traditional browser risks becoming infrastructure operating behind the scenes rather than the primary destination for users.
Anthropic is not alone in pursuing this vision. AI developers are increasingly trying to transform conversational assistants into general-purpose agents capable of managing significant portions of a user’s digital workflow.
Claude in Chrome Becomes More Autonomous
At the same time, Anthropic has pushed Claude in Chrome into general availability for paid Claude customers.
The extension can examine the webpage currently displayed and perform actions including entering text, clicking links, navigating between pages and completing forms while maintaining the user’s existing logged-in browser session.
More importantly, Claude no longer needs approval for every individual browser action.
That gives the technology considerably greater autonomy and potentially makes it useful for complex workflows involving internal dashboards, supplier portals, legacy business applications and services that do not have dedicated Claude integrations.
Enterprise administrators can impose domain restrictions and organizational controls, while users who prefer tighter oversight can retain manual approval settings.
The greater autonomy, however, raises an unavoidable question: what happens when an AI agent encounters malicious instructions online?
Anthropic Builds Three Layers of Defense
Prompt injection remains one of the most serious security challenges facing browser-operating AI.
Attackers can hide instructions inside webpages, emails or other online content in an attempt to manipulate an AI agent into ignoring the user’s actual request and performing unintended actions.
Anthropic’s earlier testing illustrated the scale of the problem. During its 2025 pilot, the company reported a 23.6% attack success rate when defenses were absent.
Anthropic says approximately a year of security work has produced a three-layer defensive architecture combining stronger model resistance, probes and classifiers.
The first layer involves training Claude against attack examples collected through automated testing, external red teams and real-world monitoring. Successful attacks can be incorporated into Anthropic’s attack library to improve subsequent defenses.
The second layer uses probes to inspect webpages and emails for signs of malicious instructions. When suspicious content is detected, Claude can be warned and may request user confirmation before continuing.
The third layer employs classifiers immediately before an action is executed. The system checks whether actions such as navigating to another website or entering information correspond with the user’s original instruction. Suspicious or mismatched actions can then be blocked.
Attack Rates Fall Sharply in Anthropic Testing
Anthropic reports dramatic improvements under its latest evaluations.
Without additional defenses, attacks reportedly achieved a 17.6% success rate against the previous-generation Claude Opus 4.5 and 3.8% against Claude Opus 5.
With probes and classifiers enabled, Anthropic reported a 0% success rate against Claude Sonnet 5, Claude Opus 5 and Claude Mythos 5, while Claude Fable 5 recorded 0.3%.
Those figures represent Anthropic’s own evaluations rather than proof that browser agents are immune from attack. The company acknowledges that prompt injection techniques continue to evolve and says it intends to continue automated attack discovery, red-team exercises and classifier improvements.
That qualification matters because moving an AI agent from answering questions to independently clicking buttons, entering data and navigating authenticated websites dramatically increases the consequences of mistakes or manipulation.
The Bigger Battle Is Over the User’s Digital Workspace
Anthropic’s browser strategy ultimately represents more than another feature launch. It points toward a future in which the AI assistant itself becomes the primary interface through which people interact with online services.
Google built enormous influence by controlling search and the browser. AI companies now see an opportunity to place intelligent agents between users and those traditional gateways.
Anthropic’s simultaneous development of Claude in Chrome and a separate built-in browser is particularly revealing. One approach allows Claude to work inside today’s browser ecosystem; the other begins reducing its dependence on that ecosystem altogether.
The competitive implications could be substantial. If AI agents become reliable enough to research information, navigate websites and execute routine digital work autonomously, users may care considerably less about which conventional browser sits underneath those experiences.
Anthropic has not eliminated the security challenge, and its own disclosures demonstrate why caution remains essential. Yet its improving defense results and expanding browser capabilities show how quickly autonomous web agents are advancing. The bigger question is no longer whether AI companies want to challenge browsers and search engines, but whether users will eventually prefer an AI agent as their main gateway to the internet.
For more details on Anthropic AI browser, visit:
https://support.claude.com/en/articles/16607400-use-the-built-in-browser-in-claude-cowork
Additional Reads:
https://thenextweb.com/news/anthropic-claude-cowork-built-in-browser-dma-choice-screen
https://www.macstories.net/news/anthropic-introduces-an-in-app-browser-for-claude-cowork
https://www.heise.de/en/news/Anthropic-is-giving-its-AI-Claude-its-own-browser-11431857.html