Product Launch2 min read

Claude Cowork Now Runs Inside Chrome's Sidebar

By , Senior AI ConsultantPublished

Anthropic has merged its office-task AI agent, Claude Cowork, into the Claude for Chrome browser extension, so Max and Team subscribers can start a task on the desktop app and finish it in the browser, right as security researchers keep finding new ways to trick the same extension into acting without permission.

Anthropic just made its two Chrome-based Claude tools work as one. Claude Cowork, the company's agent for everyday office tasks, now lives inside Claude for Chrome, the browser sidebar extension. Start a task on your phone or the desktop app, then pick it up in Chrome, or the reverse, and your history, skills, and connectors carry over automatically. Max and Team subscribers get it today; Pro users, who pay the cheapest monthly fee, get it in a few weeks.

To understand why this matters, it helps to know what these two tools actually do. Claude Code is Anthropic's product for programmers who write software. Claude Cowork, launched in January, is the plain-language version built for people who never touch code: writing reports, filling out spreadsheets, building slide decks, drafting business documents. Anthropic's own usage data has shown that most people using its agents aren't coding at all, they're doing exactly this kind of office work, which is why folding Cowork into the browser people already use for everything else is a smart distribution move.

That move also reveals a strategic choice. OpenAI built ChatGPT Atlas, an entirely separate browser. Perplexity built Comet, another standalone browser. Anthropic instead chose to stay inside Chrome, the browser most people and companies already use, and add its AI as a sidebar rather than asking anyone to switch. That is the lower-friction path: no one has to change habits, install a new browser, or move over bookmarks and passwords. It also means Anthropic doesn't have to win a browser war, it just has to be useful inside the one people already have open.

The rollout itself has been gradual for a reason. Claude for Chrome started in August last year as a small test limited to a thousand paying users, opened to all Max subscribers by late November, and reached Pro, Team, and Enterprise plans by mid-December. That caution exists because letting an AI agent click buttons and fill forms on your behalf, using your logged-in accounts, is a genuinely risky permission to hand out.

And the risk is not theoretical. Security researchers have repeatedly found flaws in the Chrome extension, including a bug that let a malicious webpage take over a user's account with no clicks required, exposing Gmail access, Google Drive files, and chat history to an attacker. Another flaw let a rogue browser extension trigger Claude's built-in actions by faking user clicks. One research team reported that the vulnerable code stayed identical across eight extension updates after they first flagged it. Anthropic itself tells users the biggest danger is a webpage hiding instructions that trick Claude into doing something the user never asked for, and it already blocks the extension entirely for healthcare organizations covered by patient privacy rules.

For a business thinking about turning this on, the calculation is simple. The convenience is real: fewer app switches, tasks that survive a closed laptop, and one history across devices. But before connecting Gmail, a shared drive, or any system with sensitive data, it is worth keeping the "ask before acting" setting on rather than letting Claude act without confirmation, and starting with tasks where a mistake costs you nothing more than wasted time. Treat the agent like a new hire on their first week: useful, but not yet trusted with the keys to everything.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable