What’s New?
Anthropic has launched a research preview of a browser-based AI agent powered by its Claude models. Called Claude for Chrome, the extension allows users to chat with Claude in a sidecar window that keeps track of everything happening in their browser. Users can also permit Claude to perform certain actions, like completing tasks on their behalf.
The pilot is limited to 1,000 subscribers on Anthropic’s Max plan, which costs between $100 and $200 per month. A waitlist is now open for other users who want access.
AI Browsers: The Next Battleground
Browser-based AI agents are becoming the latest focus for tech labs. Competitors are already moving fast: Perplexity launched its Comet browser with a task-performing AI agent, OpenAI is reportedly preparing its own AI browser, and Google has added Gemini integrations to Chrome.
The urgency of this race has been amplified by Google’s looming antitrust case. A federal judge may force Google to sell Chrome, and companies like Perplexity and OpenAI have expressed interest in acquiring it.
Safety Concerns and Protections
Anthropic warns that AI agents with browser access introduce new risks. For instance, Brave’s security team reported vulnerabilities in Comet related to prompt-injection attacks, where hidden code could trick the agent into executing harmful instructions.
To mitigate risks, Claude includes several safeguards:
- Users can limit which sites Claude accesses.
- The agent is blocked by default from visiting sites offering financial services, adult content, or pirated content.
- Claude requires user permission before taking high-risk actions such as publishing, purchasing, or sharing personal data.
These measures have reduced the success rate of prompt injection attacks from 23.6% to 11.2%.
Practical Use Cases
Anthropic’s demo shows Claude performing tasks like:
- Finding house listings on Zillow
- Summarizing Google Doc comments
- Adding items to a DoorDash cart
While capable of handling simple tasks reliably, AI agents still struggle with more complex problems. Users must remain aware of both user and agent errors.
Next Steps
The pilot program starts with 1,000 Max plan members. Based on feedback, Anthropic will gradually expand access while monitoring safety and security concerns.


