Most AI assistants that claim to ‘use the web’ are either scraping public content or borrowing access to your browser through an extension. Anthropic is taking a different approach. Claude now has its own dedicated browser, built directly into the Claude Cowork desktop app, and it runs completely separately from anything you have open. That separation is the whole point.
What the built-in browser actually does
When you give Claude a task that involves a website, a browser opens in the side panel of the desktop app. Claude then navigates pages, clicks, types, and reads content on its own. According to the official Anthropic blog post, Claude can fill in forms, pull numbers from a dashboard, or work through a vendor portal that has no integration or API connector. No extension to install, no configuration required.
The key distinction here is that Claude’s browser is not your browser. It never sees your tabs, saved passwords, or bookmarks. If you want Claude to stay signed in to specific sites, you can transfer logins from Chrome, Edge, or Firefox individually. Banking, email, and single sign-on sites are excluded by default unless you explicitly add them.
How this fits with Claude in Chrome
Anthropic already had a browser tool: the Claude in Chrome extension, which gives Claude access to a page you already have open. That product still exists and stays the default if you’re already using it. But the two tools are designed for different situations.
- Built-in browser: Best for handing off a web task entirely, like gathering research, collecting invoices from a portal, or running a multi-step workflow while you keep working on something else.
- Claude in Chrome: Best for pages you’re already viewing with accounts you’re already signed into, like updating a CRM record, working through email, or editing a document in your current session.
You can switch between them anytime in Settings, under Cowork, then Preferred browser.
Security and the prompt injection problem
Any AI agent that acts inside a browser faces prompt injection risk, where hidden instructions on a webpage try to redirect the model’s behavior. Anthropic acknowledges this directly. The built-in browser runs the same safeguards as Claude in Chrome, including checks that compare Claude’s actions against your original request. These reduce the risk but don’t eliminate it. Anthropic recommends starting with sites you already trust, which is reasonable advice for any agent-based browser tool right now.
Competitors like OpenAI’s Operator and browser-use-based agents have faced similar scrutiny. No one has fully solved prompt injection yet. Anthropic is at least being transparent about it rather than pretending the risk doesn’t exist.
Availability and pricing
The built-in browser is rolling out this week to Pro, Max, and Team plan users on the Claude desktop app across macOS, Windows, and Linux. Enterprise admins can enable it today through Organization settings. Once it reaches your account, it’s on by default. No action needed.
One practical note: the browser lives in the desktop app. You can trigger Claude to use it from the web or mobile, but only if your desktop app is open and connected. Without the desktop app, Claude in Chrome remains the only browser option.
For teams running repetitive web workflows, this is a meaningful addition. It removes the dependency on manual integrations for sites that don’t offer APIs, which in practice is most of the tools mid-sized companies actually use.




