Anthropic is launching a investigation preview of a browser-based AI supplier powered by its Claude AI models, nan institution announced connected Tuesday. The agent, Claude for Chrome, is rolling retired to a group of 1000 subscribers connected Anthropic’s Max plan, which costs betwixt $100 and $200 per month. The institution is besides opening a waitlist for different willing users.
By adding an hold to Chrome, prime users tin now chat pinch Claude successful a sidecar model that maintains discourse of everything happening connected their browser. Users tin besides springiness nan Claude supplier support to return actions successful their browser and complete immoderate tasks connected their behalf.
The browser is quickly becoming nan adjacent battleground for AI labs, which purpose to usage browser integrations to connection much seamless connections betwixt AI systems and their users. Perplexity precocious launched its ain browser, Comet, which features an AI supplier that tin offload tasks for users. OpenAI is reportedly adjacent to launching its ain AI-powered browser, which is rumored to person akin features to Comet. Meanwhile, Google itself has launched Gemini integrations pinch Chrome successful caller months.
The title to create AI-powered browser is particularly pressing fixed nan looming determination successful Google antitrust case, expected immoderate time now. The national judge successful nan lawsuit has suggested he whitethorn unit Google to waste its Chrome browser. Perplexity submitted an unsolicited $34.5 cardinal connection for Chrome, and OpenAI CEO Sam Altman suggested his institution would beryllium willing to bargain it as well.
In nan Tuesday blog post, Anthropic warned that nan emergence of AI agents pinch browser entree poses caller information risks. Last week, Brave’s information squad said it recovered that Comet’s browser supplier could beryllium susceptible to indirect prompt-injection attacks, wherever hidden codification connected a website could instrumentality nan supplier into executing malicious instructions erstwhile it processed nan page.
(Perplexity’s caput of communications Jesse Dwyer told TechCrunch successful an email that nan vulnerability Brave raised has been fixed.)
Anthropic says it hopes to usage this investigation preview arsenic a chance to drawback and reside caller information risks, however, nan institution has already introduced respective defenses against punctual injection attacks. The institution says its involution reduced nan occurrence complaint of punctual injection attacks from 23.6% to 11.2%.
Techcrunch event
San Francisco | October 27-29, 2025
For example, Anthropic says users tin limit Claude’s browser supplier from accessing definite sites successful nan app’s settings, and nan institution has, by default, blocked Claude from accessing websites that connection financial services, big content, and pirated content. The institution besides says that Claude’s browser supplier will inquire for personification support earlier “taking high-risk actions for illustration publishing, purchasing, aliases sharing individual data.”
This isn’t Anthropic’s first foray into AI models that tin power your machine screen. In October 2024, nan institution launched an AI supplier that could control your PC — however, testing astatine nan clip revealed that nan exemplary was rather slow and unreliable.
The capabilities of agentic AI models person improved rather a spot since then. TechCrunch has recovered that modern browser-using AI agents, specified arsenic Comet and ChatGPT Agent, are reasonably reliable astatine offloading elemental tasks for users. However, galore of these systems still struggle pinch much analyzable tasks.