Claude can use your browser now. Here is what that means.
The short version: Claude in Chrome is a browser extension that lets Claude operate websites for you — reading the page, typing into boxes, clicking links and filling in forms, using the logins you are already signed in with. As of 26 August 2026 it is out of pilot and available on every paid Claude plan. The real change is not that it can click; the pilot could click. It is that it stopped asking permission before every click. A classifier now checks each action against what you asked for and blocks anything that does not match. The catch worth knowing before you install it is prompt injection — hidden instructions on a page — and the off switch for the automatic clicking is in your settings.
What this actually is, in plain terms
Claude is an AI assistant made by a company called Anthropic. Until now, using it looked like a conversation: you typed something, it typed back. If you wanted it to do something on a website, you did the doing.
Claude in Chrome is a small add-on for the Chrome web browser that removes that gap. Once it is installed, Claude can see the page you are looking at and work it like a person would. Anthropic list the actions plainly: it views the page you are on, and takes actions like reading and typing text, clicking links, navigating between pages, and filling out forms.
Here is the concrete version, because this is the part that gets skipped. Picture the expenses site at your work — the one with the 1990s layout, the dropdown that never remembers your department, and eleven fields you fill in the same way every month. You open it, you tell Claude what the expenses were, and it fills the form in while you do something else. Or the supplier portal that still uses a login your predecessor set up, where checking twelve order numbers means twelve separate searches. That is the job.
Anthropic are explicit that this is the point. Many tools connect straight into Claude already. But, in their words, internal dashboards, legacy systems, and vendor portals do not — and realistically never will, because nobody is going to build an integration for a system three people use. Claude in Chrome reaches them by not integrating at all. It just drives the browser.
The sentence everybody skims past
Four words in the announcement do more work than the rest of it combined: Claude takes those actions “using your existing logins”.
It is worth sitting with that for a second. The extension runs inside your Chrome, with your session cookies. It does not have its own account for your company’s expense system. It has yours. Anything you are signed in to in that browser — your email, your CRM, your bank if you happen to be logged in — it is signed in to as well, because it is you.
That is simultaneously the entire value of the product and the entire risk of it. There is no separate permission wall between Claude and your accounts, because removing that wall is what makes it useful on the ugly old systems. Everything in the safety section further down exists to manage the consequences of that one design decision.
What actually changed on 26 August 2026
Claude in Chrome is not new. It launched as a limited pilot last year. Two things changed on the day of this announcement.
One: it is generally available on every paid Claude plan. The waiting list is gone. If you pay for Claude, you can install it. It is not available on the free tier.
Two, and this is the real headline: it stopped asking. In the pilot, Claude needed your approval for every single action — every click, every form field, one confirmation at a time. Anthropic’s wording is that Claude can now also take actions autonomously in the browser, instead of needing approval for every one.
Most coverage of this announcement will lead with “Claude can use your browser”. That was already true. What is new is that it does it without stopping to ask you, which changes the experience from supervising a tool to delegating a task — and changes what you should think about before you point it at something.
Automatic approval can be turned off. Anthropic put it in parentheses, so it is easy to miss: you can switch this off in your settings if you’d prefer to continue to approve Claude’s actions manually. If the idea of an AI clicking things unsupervised in your logged-in browser makes you uneasy, that is a completely reasonable instinct. Turn automatic approval off, use it in manual mode for a week, watch what it actually tries to do, and turn it back on when you have a feel for it. Nothing about the product requires you to start on autopilot.
How to install it
Three steps, and there is nothing hidden in them.
Be on a paid Claude plan, in Chrome
Claude in Chrome is generally available on every paid Claude plan. It does not work on the free tier. It also has to be actual Google Chrome — Anthropic state it does not run on other Chromium browsers, and not on mobile.
Install the extension from the Chrome Web Store
Install it from the Chrome Web Store, the same way as any other extension. On an Enterprise plan your admin may have to enable it first — they manage it in Organization Settings and can restrict it to a list of approved domains, so it will only operate on sites the company has allowed.
Decide how much rope to give it
Before your first real task, open your settings and decide whether you want automatic approval on or off. On means Claude acts and a classifier checks each action. Off means Claude asks you every time. Start with it off if you are new to this. Then give it something low-stakes and reversible — looking things up across a few tabs, not submitting anything.
The honest part: hidden instructions
This is the section the excited coverage will skip, and Anthropic themselves do not. An AI agent that works in your browser is vulnerable to something called prompt injection.
It means exactly what it sounds like. Someone hides instructions in content that Claude is going to read — a web page, an email, a form field — written for the AI rather than for you. You never see them. Claude does, and it can mistake them for part of the job.
Anthropic’s own worked example is the clearest way to understand it, so here it is as they tell it: you ask Claude to draft replies to your emails, and a hidden instruction in one message could tell Claude to forward your other emails to the attacker. Nothing was hacked. No password was stolen. Claude simply read a sentence in an email and treated it as an instruction — while signed in as you.
Anthropic describe three layers of defence against this, and they are worth understanding because they explain what is and is not being promised.
One: Claude recognises more attacks. The model is trained against a growing library of real prompt injection attacks, collected from Anthropic’s own automated attackers, outside red-teamers, and monitoring in the wild. When a new attack works, it goes into the library and informs the next model. This is the slow layer — it improves between model releases, not during your session.
Two: probes screen the content first. Web content reaches Claude as the result of a tool call — Claude asks to read a page, and the page comes back as the answer. Trained probes scan those results for likely injections before Claude acts on them. When a probe fires, Claude is warned to treat that content with suspicion and, if needed, to check with you before doing anything.
Three: actions are verified before they run. This is the layer that makes the autonomy possible. A classifier reviews each action Claude is about to take — opening a new site, typing into a page — and checks it against what you originally asked for. In Anthropic’s words: if the action doesn’t match your request, it’s blocked. It is the same mechanism as auto mode in Claude Code.
Read together, the three layers say something specific: the promise is not that Claude cannot be fooled by a web page. It is that a fooled Claude should not be able to act on it, because the action would not match what you asked for.
The numbers, including the ones that are less flattering
Anthropic published test results alongside the announcement, and the headline everyone will quote is that no attacks succeeded. That is true, with conditions, and the conditions are the interesting part. Their current evaluation uses stronger attacks written by professional red-teamers.
| Setup | Attacks that succeeded |
|---|---|
| Opus 4.5, no extra safeguards | 17.6% |
| Opus 5, no extra safeguards | 3.8% |
| Opus 4.5 with November 2025’s best probes | 16.7% |
| Sonnet 5, Opus 5, Mythos 5 — probes + safety classifier | None succeeded |
| Fable 5 — probes + safety classifier | 0.3% |
Three pieces of context that matter for reading that table honestly.
First, those percentages are of attacks that reached the model. Anthropic footnote this directly: not all attacks reach — that is, are seen by — the model, because sometimes Claude’s own choices mean it never encounters the malicious instruction at all. So these are not success rates against all attempts.
Second, “no attacks succeeded” is a statement about the newest models with all the safeguards switched on. The 3.8% figure is the same generation of model with them off. The safeguards are doing real work, and that is the point of the table — but it is a claim about a system, not about a model being incorruptible.
Third, and most usefully, Anthropic do not claim the problem is solved. Their own words: “Prompt injection remains a moving target.” They also say they have manually verified that every successful break was in a low-severity scenario, and that they are working to mitigate them. That is a fair and unusually candid way to ship something, and it is the right frame for deciding what to let it near.
What I would keep it well away from
This is a judgement call rather than a rule from Anthropic, so treat it as one. Given that the extension acts with your live logins and that hidden-instruction attacks are, by Anthropic’s own account, an unsolved and moving problem, here is where I would draw the line.
- Anything that moves money. Banking, payment portals, anywhere with a stored card. The cost of a rare failure is not symmetrical with the time saved.
- Your main email, on autopilot. Email is the exact medium Anthropic’s own attack example uses, because an inbox is full of text written by strangers. If you want help with email, use it with automatic approval switched off.
- Anything irreversible. Sending, publishing, deleting, submitting a final application. Prefer tasks where a mistake is a nuisance rather than an incident.
- Other people’s personal data. If a page holds customer records or medical information, the question is not only whether you trust the tool but whether you have the standing to make that call.
- Sites full of content you did not write. Comment threads, forums, shared documents from outside your company, anything with user-submitted text. That is where hidden instructions live.
The pattern behind all five: it is safest on a boring internal system where the only text on the page was put there by your own company, and least safe anywhere strangers can write. Which, conveniently, is also exactly the job Anthropic built it for.
What it still cannot do
Three limits, all stated plainly in the announcement, and all worth knowing before you go looking for a feature that is not there.
It runs on Chrome only — not on other Chromium browsers such as Edge, Brave or Arc. It does not run on mobile yet. And it cannot reach files on your computer or your other applications; that still needs the Claude desktop app. The browser extension is for the browser, and nothing beyond it.
If you have seen an AI go shopping for you in its own separate browser window, that is a different thing and it is worth understanding the difference — we covered it in send an AI shopping: agent mode, explained honestly. The short version: that opens a fresh browser that is signed in to nothing, which makes it safer and much less useful. This drives yours. And if you want to know what Claude is writing down about you while you use it, that list is readable and editable — here is where Claude’s memory lives and how to wipe it.
Questions people actually ask
What is Claude in Chrome, in plain English?
It is a Chrome extension that lets Claude use your browser the way you would. It can look at the page you are on, read the text, type into boxes, click links, move between pages and fill in forms. Crucially it does that inside your own browser, so it is already signed in to everything you are signed in to. It is not a chat window that talks about websites; it is a thing that operates them.
Do I have to pay for Claude in Chrome?
Yes. As of 26 August 2026 it is generally available on every paid Claude plan. It is not on the free tier. If you are on a paid plan you install it from the Chrome Web Store and it works.
What actually changed on 26 August 2026?
Two things. It left the pilot and became generally available on all paid plans. And, more importantly for how it feels to use, Claude can now take actions autonomously instead of asking you to approve every single one. During the pilot it stopped and asked before each click. Now a safety classifier checks each action against what you asked for, and if it matches, Claude just does it.
Can I make it ask me before every click again?
Yes, and this is the single most useful sentence in Anthropic's announcement. Automatic approval can be switched off in your settings, and Claude goes back to asking you to approve its actions manually. If you are nervous about the whole idea, turn this off first and watch it work for a while before you let it run on its own.
Is Claude in Chrome safe? What is prompt injection?
Prompt injection is the real risk and Anthropic names it themselves. It means malicious instructions hidden in a website, an email or a document that try to trick an AI agent into acting against your wishes. Their own worked example: you ask Claude to draft replies to your emails, and a hidden instruction buried in one message tells Claude to forward your other emails to an attacker. There are three layers of defence against it, and on Anthropic's most recent tests no attacks succeeded against Sonnet 5, Opus 5 or Mythos 5 with all safeguards running. Their own closing line is still that prompt injection remains a moving target.
How well do the safeguards actually work?
On Anthropic's current evaluation, using stronger attacks written by professional red-teamers, attacks that reached the model succeeded 17.6% of the time against Opus 4.5 and 3.8% of the time against Opus 5 before any additional safeguards. With probes plus the safety classifier switched on, no attacks succeeded against Sonnet 5, Opus 5 or Mythos 5, and 0.3% succeeded against Fable 5. Anthropic say they have manually checked that all successful breaks were low-severity, and that they are working to mitigate them.
What can Claude in Chrome not do?
Three limits, all stated in the announcement. It does not run on other Chromium browsers, only on Chrome. It does not run on mobile yet. And it cannot touch files on your computer or work with your other applications, which still needs the Claude desktop app.
Why would I want this if Claude already connects to my apps?
Because most things do not connect. Anthropic's reasoning is that plenty of tools plug straight into Claude, but internal dashboards, legacy systems and vendor portals do not, and never will. Those are exactly the ugly websites where the tedious work lives. Claude in Chrome reaches them for the simple reason that it is not integrating with them at all, it is just driving the browser you already use to open them.
Can my company block it?
Yes. On Enterprise plans, admins can manage the extension in Organization Settings and limit it to approved domains, so it only operates on sites the company has allowed.
Want this built for you?
We write these memos because we build this stuff every day. If you want it working in your business instead of sitting on your reading list, that is literally our job.