Agentic Browsing
The Claude app just grew
a browser of its own.
Browser automation used to mean installing the Claude in Chrome extension first. The Claude desktop app now ships a built-in browser, alongside the separate Claude in Chrome extension — here's what this move means in the middle of an already-crowded agentic-browser race.
The "AI browser" race
was already underway
Through 2026, agentic browsing — AI that operates a browser on its own — became one of the main battlegrounds among AI labs. OpenAI shipped Atlas, its own browser built into ChatGPT; Perplexity pushed its AI browser Comet; Google went deeper on integrating Gemini directly into Chrome itself. Anthropic had entered this space via the Claude in Chrome extension, but that approach stayed limited to adding capability on top of an existing browser.
Now, the Claude desktop app itself ships a built-in browser, offered as a separate option alongside the Chrome extension. The Chrome extension isn't going away — the real story here is the two-track setup: "add capability to the Chrome you already use" versus "run everything inside a dedicated Claude environment."
Extension or dedicated environment?
The right pick depends on the job
Same "Claude that browses for you," but where it runs changes what it's good for.
| Claude in Chrome (extension) | Claude desktop's built-in browser (new) |
|---|---|
| Runs inside your everyday Chrome profile | Runs in a separate, isolated environment |
| Uses your already-logged-in personal accounts directly | Easier to keep separate from personal use, e.g. for work |
| Coexists with your bookmarks and other extensions | Everything happens inside the Claude app itself |
If you want to keep using your everyday browsing setup as-is, the Chrome extension fits better. But for enterprise users or anyone who wants to keep their personal browser environment separate from AI agent work, the dedicated built-in browser is easier to manage. That's especially true when handing an AI agent access to sensitive business systems — running it outside your normal Chrome profile keeps the risk more contained.
Who benefits, and how
The appeal shifts depending on the use case.
Individual users
A useful option for anyone who didn't want yet another Chrome extension installed. If you're already comfortable with the Chrome-extension setup, nothing changes for you for now.
Companies and IT admins
If you want to separate personal Chrome profiles from AI agent work on company devices, the built-in browser can offer a cleaner boundary for permission management.
Developers and teams building agentic workflows
Since Anthropic now controls more of the browsing execution environment directly, how this deepens integration with Computer Use-style APIs and agent workflows going forward is worth watching.
Not extending your browser —
giving it a place of its own.
What happens next
Worth watching: how much of the Chrome extension's role the built-in browser eventually takes over, or whether Anthropic draws a clear line between the two use cases instead. The agentic-browser race — now a three-way contest between Anthropic, OpenAI's Atlas, and Perplexity's Comet — will increasingly be decided by differences in usability and safety design across the players.
If you want to try it, a practical first step is comparing the built-in browser against the Chrome extension on low-stakes tasks (research, information gathering) to see which setup actually fits how you work.
The shared risk of agentic
browsers hasn't gone away
Whether it's a built-in browser or an extension, any system where an AI agent reads and acts on web pages carries a shared risk: prompt injection, where the AI mistakes instructions embedded in a malicious page for the user's own commands and acts on them. That's a known issue raised against OpenAI's Atlas and Perplexity's Comet alike, and Claude's new built-in browser isn't inherently immune to it either.
As of today's announcement, the full permission model and sandboxing design specific to the built-in browser haven't been fully detailed, so companies considering serious production use should confirm directly how far the operating scope can actually be restricted. Anthropic's support documentation already tells Claude in Chrome users to review their own permission scope carefully, and the same kind of diligence will likely apply to the built-in browser too. Having two paths gives users more choice, but deciding which one to use is itself now a new thing to think through.