Claude already has his own AI agent for Chrome

Claude's AI will be able to operate directly in the browser. However, the company advises users about its security risks.
August 27, 2025

Anthropic, the company behind the popular AI model Claude, has just taken a significant step forward in its evolution: it now intends for its assistant to work directly from your Chrome browser. In practice, this means that Claude will no longer be limited to merely answering questions or analyzing documents. Instead, it will be able to see what you see, click on buttons, fill out forms, and assist you with your calendar or email.

At first glance, this sounds excellent: an assistant that not only responds, but takes action on your behalf. However, it naturally gives rise to numerous concerns regarding security, and, perhaps surprisingly, it is Anthropic itself that has chosen to highlight these issues.

Claude moves to your browser (carefully)

According to Anthropic, AI assistants operating within the browser represent the future: nearly everything we do takes place within a tab. Granting Claude the ability to function in this context makes it vastly more useful. However, opening this door also introduces risks. For this reason, the extension is currently being tested in a controlled phase, limited to just 1,000 users of the Max plan, who have been carefully selected as “trusted users” to help refine both its functionality and its security.

Their mission is to report any unusual behavior or attempted attacks, allowing Anthropic to strengthen defenses prior to a broader release.

What is the purpose of the Pilot extension?

With this extension, Claude can:

  • Manage calendars and schedule meetings.
  • Draft email responses.
  • Automate expense reports.
  • Test new functionalities on websites quickly and in a controlled manner.

Using Claude for Chrome with Google Calendar

The initial results are promising, but Anthropic acknowledges that there are still security issues to be resolved prior to a large-scale launch. In fact, the company specifically requests that users refrain from using the extension for “financial transactions, password management, or anything involving sensitive personal data. Start with trusted websites and familiar workflows where you feel comfortable allowing Claude to take actions. Never use it for critical decisions without careful supervision.” 

Additionally, users are reminded that the following uses are not allowed:

  • Engaging in stock market or investment activities
  • Bypassing captchas
  • Entering sensitive data
  • Collecting or extracting facial images

The sensitive side: prompt injection

This is where it becomes delicate. By granting Claude access to the browser, Anthropic explains that it also opens the door to a type of attack known as prompt injection. The concept involves hiding malicious instructions within webpages, emails, or documents, with the intent to deceive the AI into performing actions you would never request.

For example, an email that appears entirely normal could contain hidden text instructing Claude to delete all your emails or copy personal data. In internal testing, without any defenses, Claude fell victim to this type of trap 23.6% of the time. In one particular case, an email disguised as a “security alert” succeeded in deleting the entire inbox.

In any case, the company explains that prior to giving testers access to the extension, Anthropic implemented several layers of security:

  • Clear access permissions: you decide which sites Claude may access, and you may revoke these permissions at any time.
  • Mandatory confirmations: if Claude is to perform a sensitive action, such as making a purchase or publishing sensitive information, your explicit approval will be required in advance.
  • Reinforced internal prompts: instructions that guide Claude to be suspicious of questionable requests.
  • Blocking of high-risk websites: financial websites, adult content, and pirate sites are restricted from the outset.

As a result of these measures, the success rate of such attacks was reduced to 11.2%, and in specific scenarios within the browser (such as forms with hidden fields), the rate dropped to 0%.

As can be seen, for now, the company is proceeding with slow and controlled steps. If the pilot phase is successful, it is likely that we shall see a broader rollout. There is still work to be done to ensure that using an autonomous assistant in the browser is as secure as it is convenient, but Claude for Chrome represents an important first step toward a more productive future.

At the moment, you may join the waiting list here.

Other articles related to

Published by

Content manager in Marketing4eCommerce

Stay up to date!

Únete a nuestro canal de Telegram

All you need to know!

Sign up for our newsletter and receive our best articles on eCommerce and digital marketing in your email for free.