Anthropic is previewing a browser based Claude agent that runs inside Chrome. The company invited a thousand subscribers on its Max plan into a research preview and opened a waitlist for other users. The pilot lets Claude sit in a side panel so it can follow what a user is doing in the browser. Anthropic calls this an early test meant to find new safety issues before a wider release.
What the extension does and how it works
The Claude for Chrome extension lets the model keep context of the pages a user visits. Claude can read text on a page click buttons and fill simple forms when the user gives permission. The agent appears in a side panel so it does not take over the main window. Users can ask Claude to fetch information summarize pages and perform small tasks while they continue browsing. Anthropic also published a support guide that explains how to install and use the extension.

Who can try the preview and how to join
Access for the research preview is limited at first to a set of Anthropic Max plan customers. The Max plan sits in a higher price tier for power users and enterprises. People who want to try the pilot can sign up on the waitlist and then install the extension when they receive an invite. Anthropic asks testers to avoid sensitive or safety critical setups while the company expands testing.
Why Anthropic calls this a research preview
Anthropic warns that agents that act inside a browser introduce new risks. Recent public work by other teams showed how an agent can be tricked by hidden or malicious page content. Anthropic says it sees the browser as an important place to study those risks and to build defenses before broad release. The company frames the invitation as a way to find and fix novel attack types that only appear when an assistant can act directly inside webpages.
Safety measures Anthropic has built
Anthropic already added several safety layers for browser use. The extension gives users site level controls so they can grant and revoke Claude access to specific websites. The agent asks for confirmation before taking high risk actions such as posting publishing or making purchases. Anthropic also blocks whole categories of sites by default including financial services adult content and piracy sites. In internal tests the company reports that layered mitigations reduced a measured prompt injection success rate from 23.6 percent to 11.2 percent. Anthropic says it will expand red teaming and testing to push those numbers lower.
How this compares with other browser agents
Other teams are also building browser agents and AI aware browsers. Perplexity launched a browser called Comet that includes an agent. Brave published a security review that found attack modes where a page could trick an agent into taking unintended actions. Perplexity says it patched the issue. The broader field shows both potential and risk. Anthropic positions its preview as a cautious step that will let the company learn before it ships more powerful automation.

Limits and real world reliability
Agentic systems handle many simple web tasks well but they still struggle on complex or sensitive workflows. Anthropic noted prior experiments where similar agents were slow or unreliable at scale. The company and outside researchers say that hands on review and careful controls are essential before people give agents broad authority. For this reason Anthropic keeps the pilot small and requires explicit user permission for risky actions.
Privacy controls and user choices Anthropic gives users the ability to limit what Claude can see and do. Users control site permissions and can switch off autonomous behavior. The agent will ask before it shares personal data or performs transactions. These settings are central to Anthropic plans and to how the company frames safety as a priority in agent development.