Anthropic just gave its AI assistant its own hands for the internet.
The company has built a full web browser directly into the Claude desktop app, the one that runs Claude Cowork, Anthropic's tool for handing off multi-step work like filling out forms, organizing files, and pulling numbers off a screen. Until now, if Claude needed to visit a website with no direct software connection built for it, you had to install a separate Chrome extension and let Claude ride along inside your own browser tabs. Now the browser lives inside Claude itself.
Ask Claude to check an order status on a supplier's site or fill out a form on a government portal, and a browser window opens right next to your work. It logs in, clicks, types, and reads the page much like a person would.
This matters more than it sounds. A large share of business software, insurance claim systems, supplier dashboards, government filing portals, older inventory tools, was never built with a modern connector that lets outside software talk to it directly. The only way in has always been a person clicking through a website by hand. Anthropic just handed its AI assistant that same access. If your company still runs parts of its operations through these kinds of browser based portals, and most companies quietly do, this is the kind of task Claude can now take off someone's desk without a custom software project.
Anthropic kept the new browser walled off from your everyday one on purpose. It cannot see your open tabs, saved bookmarks, or stored passwords. You can hand over specific website logins one at a time, but Anthropic blocks this for banking and email sites, which tells you plainly where the company sees the real danger.
That danger has a name: prompt injection. A webpage can contain hidden text that a human visitor never notices but that an AI reading the page might follow as if you had typed it yourself. Anthropic's own safety testing on its newest model found that attackers hijacked its browsing assistant this way in roughly one out of three attempts once protective safeguards were switched off. With those safeguards turned on, that rate dropped sharply, though not to zero. That number came from Anthropic itself, and it is likely why the company tells users to only point this browser at websites they already trust.
The timing lines up with a bigger pattern across the industry. OpenAI spent under a year building Atlas, a standalone browser meant to put ChatGPT at the center of web browsing, before quietly shutting it down this August and folding the same capability into its regular desktop app instead. Anthropic just reached the same destination from the opposite direction, building a browser into the app it already had rather than launching a separate product. Both companies landed on the same conclusion: people do not want another browser to manage, they want their AI assistant to reach the web from wherever they are already working.
For any business still deciding whether AI can save real hours on the boring parts of the job, portal based paperwork is now a live use case worth testing. Just keep it away from banking and email until the safety numbers improve.