Anthropic is rolling out a browser built directly into Claude Cowork, letting the agent open, navigate, and fill out web pages without borrowing the user’s own Chrome session. The feature reaches Pro, Max, and Team plans in the desktop app this week, with Enterprise admins able to switch it on for their organization immediately.

The distinction matters more than it first sounds. Claude has been able to act inside a browser since Anthropic shipped the Claude in Chrome extension, but that mode hands the agent access to whatever tabs, cookies, and sessions the user already has open. The new built-in browser is a separate instance that starts empty. Anthropic says it never sees a user’s existing tabs, bookmarks, or passwords, and any login has to be moved across one site at a time out of Chrome, Edge or Firefox.

That separation is the actual product decision here, not the fact that an AI agent can click buttons and fill forms. Plenty of agent tools already do that. What Anthropic is selling is a permission boundary: a task that needs “a browser” (pulling invoices from a vendor portal, filling out a form on a site with no API) no longer means handing over the browser where someone is already logged into their bank, their mail and their single sign-on. Anthropic says those categories are excluded by default unless a user opts them in.

The company frames the two modes as complementary rather than a replacement. Claude in Chrome stays the default for work on a page already open, such as updating a CRM or editing a document. The built-in browser is meant for tasks the user hands off entirely while continuing other work.

Prompt injection is the obvious risk in any system where an agent reads and acts on arbitrary web content, and Anthropic addresses it directly rather than leaving the gap for readers to notice themselves. The company states that the feature inherits every prompt injection risk that comes with letting an agent drive a browser at all, where text hidden in a page tries to redirect the model’s actions, and that it runs the same review checks used in Claude in Chrome. Anthropic also says those safeguards reduce but do not eliminate the risk, and recommends starting on sites a user already trusts. That is a more direct acknowledgment than most vendors offer, but it is still a company describing its own mitigations without independent testing to confirm how often they hold.

One question the announcement does not resolve is credential scope in practice: once a login is carried over to the built-in browser for one site, what stops a task from wandering into an adjacent page under the same domain, and what audit trail exists if it does. Anthropic describes the browser as isolated and the exclusions as default, but does not detail how session boundaries are enforced once credentials are in play across a multi-step agentic task.

The bigger pattern is that this is now table stakes. OpenAI, Google, and Perplexity have each shipped their own agent browsing modes over the past year, and Anthropic’s version is notable mainly for how explicitly it separates “an agent’s browser” from “your browser” as a permissions model rather than a feature toggle. That framing may end up mattering more than the underlying capability, since the capability itself (click, type, read a page) is no longer differentiated.

For teams already routing work through Cowork, the practical decision is which tasks get delegated to the isolated browser versus kept in Claude in Chrome, and that choice should track exactly which credentials a task actually needs rather than which mode is more convenient to enable.

Announced by Anthropic on 26 August 2026.