Claude Cowork's newest browser update changes the product from a chat assistant that can talk about websites into an agent that can work inside them.
Anthropic's help center now says Claude Cowork has a browser built into the Claude Desktop app. When a Cowork task needs a website, a browser opens beside the task, and Claude can read pages, click, type, navigate links, and fill forms while the user watches.
That sounds like a small interface change. It is not. It gives Claude Cowork a more complete path for web work without requiring the user to install the Chrome extension or hand over their active browser tabs.
Watch the related demo
Anthropic has an official short video showing Claude Cowork running from the Chrome side panel. That is a different surface from the new Desktop built-in browser, but it shows the same broader direction: Claude moving from chat into live browser work.
What changed
Cowork already had web-adjacent paths. Claude in Chrome lets the assistant work inside the user's Chrome browser. Claude's ordinary web tools can search and fetch pages. Claude Code has also been moving toward browser-based verification for developers.
The new Cowork built-in browser is different because it is part of Claude Desktop. Anthropic says it is rolling out gradually this week to Cowork in Claude Desktop for macOS, Windows, and Linux beta on Pro, Max, and Team plans, plus Enterprise plans where an owner enables it.
When available, Claude can open websites in a side panel next to the Cowork task. The browser is separate from the user's normal browser and does not rely on Chrome. If the desktop app stays open and online, a task started on desktop can continue to be steered from Claude on web or mobile.
That makes the practical pitch clear: assign a web task, keep your own browser clean, and watch Claude do the page work in a contained environment.
Built-in browser versus Chrome
The choice now matters.
Claude in Chrome is best when the work is already happening in the user's own Chrome tab. It can use the page in front of the user, with the accounts they are already signed in to, and the Chrome side panel can run Cowork sessions for supported plans.
The built-in browser is best when the user wants Claude to handle a web workflow without touching their personal browser state. Anthropic says it does not see saved logins unless the user chooses to import them. The built-in browser can also remember logins across Cowork sessions once the user signs in inside it, which is convenient but increases the importance of choosing sites carefully.
Anthropic says users can choose the default under Settings > Cowork > Preferred browser. If someone already uses Claude in Chrome, that remains the default for Cowork web tasks; otherwise, the built-in browser becomes the default once it is available.
Why it matters for work agents
Browser use is one of the missing pieces in practical AI agents.
A lot of real work does not happen in clean APIs. It happens in admin dashboards, vendor portals, CRMs, analytics screens, help centers, webmail, spreadsheets, forms, and custom internal tools. An agent that can only summarize a pasted page is useful, but it still depends on the human to operate the interface.
An agent that can see the page, click through a flow, fill fields, compare data, and report back is closer to a real assistant.
For professionals, the near-term use cases are obvious:
- collecting information from public pages
- comparing product or vendor details across tabs
- filling low-risk forms
- preparing drafts in web apps
- checking dashboards and summarizing changes
- navigating docs while producing a report
For teams, the more important shift is control. If the browser is built into Claude Desktop, organizations can think about it as a managed work surface rather than a loose collection of extensions, screen shares, and improvised browser automation tools.
The safety tradeoff
Anthropic is also explicit that this is risky.
The built-in browser runs similar safeguards to Claude in Chrome. Claude asks before acting on a site for the first time, high-risk sites are blocked, and actions are checked against the user's stated task. But Anthropic's own guidance says browser agents can be targeted by prompt injection, where hidden instructions on a webpage try to redirect the model.
That warning is not theoretical. A browser agent reads untrusted pages by design. Those pages can include invisible text, deceptive UI, malicious downloads, confusing pop-ups, or instructions that conflict with what the user actually wanted.
The right way to use this feature is therefore conservative:
- start with sites you trust
- avoid banking, medical, legal, payroll, and sensitive personal-data workflows
- do not import cookies casually
- watch tasks that can send messages, spend money, delete records, or change account settings
- stop the task if Claude appears to follow the page instead of the user
The built-in browser makes Claude Cowork more useful, but it also makes permission boundaries more important.
The bigger product signal
Claude Cowork is becoming less like a chatbot mode and more like a general work agent.
Anthropic describes Cowork as using the same agentic architecture that powers Claude Code, but without requiring a terminal. It can take on multi-step tasks, run sessions in the cloud, use projects, work across desktop, web, and mobile, and now operate a browser surface that is not simply the user's own Chrome window.
That is the competitive story. Every major AI platform is trying to move from answer generation to task completion. The hard part is not just model intelligence. It is the surrounding harness: files, browser, apps, permissions, safety checks, memory, scheduling, and a clear place for the human to watch and interrupt.
The built-in browser is one of those harness pieces.
It will not make Cowork trustworthy enough for every website. It will make Cowork much easier to test on ordinary web work, especially for users who do not want to install a browser extension or expose their active Chrome session.
For now, the best framing is simple: Claude Cowork can increasingly work where knowledge work actually happens. The browser is no longer just a source of information. It is becoming the workspace.