Anthropic has rebuilt the side panel of its Claude in Chrome extension to host a complete Claude Cowork workspace, the company said on the product page for the tool. Skills, plugins and connectors a user has already configured elsewhere in their Claude account now load automatically inside the browser, and conversations are stored against the account rather than a single device, so a session started in Chrome can pick up on desktop, web or mobile. That is a structural shift, not a feature bump. The extension stops being a place a user visits to ask about the open tab and becomes a layer that carries an agent’s memory and toolset into whatever the user is already doing.
Anthropic’s description of what the tool does is broad. According to the page, Claude in Chrome can:
- read a signed-in page, click buttons, type text and complete forms
- extract figures from an analytics dashboard and turn them into a written summary
- sort a Google Drive account into folders and flag duplicate or stale files
- scan a calendar and related email threads to flag which meetings need prep
- visit competitor websites and pass the findings to Cowork for a formatted slide deck
- cross-reference call attendees against CRM records and draft activity log entries
Anthropic frames each of these as something a user reviews and approves, not something Claude executes unsupervised. The page carries no independent benchmark results or third-party testing of the claims, which is expected: it is Anthropic’s own marketing copy for the extension.
The framing matters more than any single capability on the list. OpenAI has pushed similar ground with browsing features built into ChatGPT and its Atlas browser, and Google has moved Gemini deeper into Chrome and Android as an assistant that reads whatever is on screen. All three companies are chasing the same position: an agent that sits on top of the browser or the operating system, available wherever a person is already working, rather than a destination opened in a separate tab. Whoever owns that layer keeps the daily habit, and the habit is worth more over time than any one query.
Google made a comparable push in 2024, wiring generative AI directly into Workspace apps. Adoption numbers from that rollout were never made public, a reminder that shipping an integration and getting people to route real work through it are separate problems.
The security section of the page deserves as much attention as the capability list, because an agent with standing access to a live browser tab also carries standing exposure to whatever that tab can do. Anthropic acknowledges that a webpage can hide instructions meant to redirect the model, a known failure mode called prompt injection, and says a separate classifier screens each action for risk before it runs. It offers a Permissions Mode that grants reach to a single site at a time, and it says purchases and other irreversible actions always wait for a human. On Team and Enterprise plans, administrators can disable the extension organization-wide or set site allow and block lists. Anthropic itself recommends keeping Claude away from banking and health records and any credentialed workflow a user would not hand to another employee, which says something about how far the company trusts its own defenses today.
A security-conscious team weighing this should ask who controls the allowlist before a shared browser profile gets access, whether the prompt-injection classifier’s decisions are logged for review, and whether connectors like CRM, Drive and analytics tools stay read-only until a person signs off. Teams already running Claude Cowork should treat this less as a browser update and more as the arrival of an always-on agent layer, and should write the permission policy this quarter before employees write their own.
Anthropic detailed the update on its Claude in Chrome product page, announced in August 2026.