Anthropic has announced a research preview of its new browser-based AI agent, Claude for Chrome, powered by the company’s Claude AI models. The rollout will initially be available to a select group of 1,000 subscribers on Anthropic’s Max plan, which costs between $100 and $200 per month. A waitlist has also been opened for other interested users.
The new AI agent integrates directly into Chrome via an extension, allowing users to chat with Claude in a sidecar window that maintains context across all browser activity. Users can also grant Claude permission to perform tasks on their behalf, such as navigating sites or interacting with content.
The move highlights the growing importance of browsers as the next battleground for AI companies, as they seek more seamless ways for AI systems to assist users. Competitors are already active in this space: Perplexity recently launched Comet, an AI-powered browser agent capable of handling user tasks, and OpenAI is reportedly preparing its own AI-integrated browser. Google has also introduced Gemini integrations with Chrome in recent months.
The push for AI-enhanced browsers is taking on added urgency amid Google’s looming antitrust case. A federal judge has indicated that Google could be forced to sell Chrome, prompting interest from competitors. Perplexity has submitted an unsolicited $34.5 billion bid for the browser, while OpenAI CEO Sam Altman has signaled that his company would also consider purchasing it.
Anthropic, however, emphasized potential safety risks associated with AI agents that can access users’ browsers. In a blog post, the company noted that modern agents could be vulnerable to prompt-injection attacks, where malicious websites trick the AI into executing harmful instructions. Brave’s security team recently identified such vulnerabilities in Comet, though Perplexity confirmed the issues have been fixed.
To mitigate these risks, Anthropic has implemented several safeguards in Claude for Chrome. These include limiting site access, blocking certain categories of websites (such as financial services, adult content, and pirated material), and requiring user permission before performing high-risk actions like publishing content, making purchases, or sharing personal data. Early tests show these interventions have reduced the success rate of prompt-injection attacks from 23.6% to 11.2%.
This release builds on Anthropic’s prior experiments with AI agents capable of controlling computers. In October 2024, the company launched a PC-controlling AI agent, though early versions were slow and unreliable. Since then, agentic AI models have improved, with TechCrunch noting that modern browser-using agents, such as Comet and ChatGPT Agent, can reliably handle simple tasks—though complex problems remain challenging.

