Anthropic integrates browser into Claude desktop app for Pro, Max, Team users

Serge Bulaev

Serge Bulaev

Anthropic has added a built-in browser to its Claude Cowork desktop app for Pro, Max, and Team users. This browser may let Claude perform web tasks without seeing users' personal tabs or passwords, and appears to keep data in a secure, isolated environment. Anthropic says the browser uses several safety layers, including isolation, safety checks, and permission requests, and lets users choose how much to approve actions. Early reports suggest business users are adopting the feature, but it remains to be seen how well its privacy approach will satisfy security teams.

Anthropic integrates browser into Claude desktop app for Pro, Max, Team users

Anthropic has integrated a built-in browser into its Claude Cowork desktop app, offering a powerful new tool for Pro, Max, and Team subscribers. This feature allows the AI to perform web-based tasks in a dedicated, secure environment, addressing the critical need for robust privacy while enabling advanced automation. The browser operates in a separate window, allowing Claude to read, click, and type on web pages without accessing a user's personal tabs, bookmarks, or saved passwords.

How the In-App Browser Enhances Security

The Claude built-in browser provides a secure method for web automation by running tasks in an isolated, server-side sandbox. This separation ensures the AI agent cannot access the user's local browser context, including personal tabs, history, or passwords, thereby protecting sensitive corporate and personal data.

Each browsing session initiated in Claude Cowork runs in what Anthropic calls an "isolated, temporary environment" on its servers. This design prevents the AI from reaching a user's local network or files unless explicitly permitted through Cowork settings (Use Claude Cowork safely). While the agent can scroll, follow links, and input text, it defaults to blocking sensitive domains for banking, email, and single sign-on (SSO) unless a user manually provides credentials for the session.

A Multi-Layered Safety Model

Anthropic has implemented a five-part defense model to ensure user control and safety. The framework includes session isolation, a prompt-injection classifier, domain allow-and-block lists, and explicit user permission requests for sensitive actions. A public post from the company states that "a safety classifier validates each action before it's performed" to confirm it aligns with the user's original request (Claude blog).

To manage the agent's autonomy, users can select one of three approval levels for each session:

  • Manually approve: Requires explicit user confirmation for every step the agent takes.
  • Automatically approve: Allows the agent to proceed with actions deemed low-risk by the safety model, pausing only for sensitive operations.
  • Skip all approvals: Grants the agent full autonomy for the current session, offering the fastest workflow.

While manual mode provides maximum control, reviewers note it can be slow for complex tasks, making automatic approval a more practical balance for most business workflows.

Rollout and Early Adoption Trends

The built-in browser feature was rolled out to all Pro, Max, and Team desktop users in late August. For Team workspaces, the feature is enabled by default, though administrators retain the option to disable it.

Early data highlights its adoption for business-centric tasks. According to company metrics from May 2026, business process automation represented approximately 33% of Cowork sessions, while software development accounted for about 9%. This suggests that the majority of use cases are focused on non-coding operational work.

Comparison with Competing AI Browsers

In the landscape of AI browser agents, Anthropic's solution occupies a privacy-focused middle ground. It stands in contrast to products like Perplexity Comet, which may retain full access to a user's logged-in sessions for greater automation, and alternatives like Brave Leo, which prioritizes privacy with local processing and no IP logging.

Anthropic's strategy relies on server-side isolation and sophisticated classifier gating to strike a balance between agent capability and enterprise-level control. As more organizations test the feature, its effectiveness in satisfying corporate security standards will become a key factor in its broader adoption.