On 26 August 2026, Anthropic shipped a browser built into Claude Cowork on the desktop app—and, the same day, made Claude in Chrome generally available on every paid plan. For US small and midsize businesses, the headline is not “AI can click now.” It is a sharper ops decision: when should an agent click through a portal, when should it work in the Chrome tab you already have open, and when should you stop clicking and build a real connector?
This guide is for founders, product owners, and ops leads who need a policy before 10 September 2026, when Enterprise defaults for both browser paths flip on unless an admin turns them off. It is not another AI-agents explainer or MCP connectivity guide, and it is not about coding-agent governance. Softix builds custom software and web apps for teams that outgrow “have Claude fill the form” and need audit logs and systems of record.
What shipped on 26 August 2026
Two related products, two different jobs.
Built-in browser in Claude Cowork
Anthropic’s product post describes a browser that opens in a side panel inside the Claude desktop app. Claude can navigate, read, click, type, and fill forms—no extension, and nothing shared from your own browser unless you import logins. It is rolling out that week to Pro, Max, and Team on macOS, Windows, and Linux (Linux in beta). Once it reaches you on those plans, it is on by default. Enterprise owners can enable it from day one.
It is Claude’s browser, not yours: no tabs, bookmarks, or passwords from your profile. Import saved logins site by site from Chrome, Edge, or Firefox on macOS, and from Firefox on Windows and Linux. Banking, email, and SSO stay unchecked unless you include them. Logins you create inside the built-in browser persist across Cowork sessions on that computer—treat import as a security decision.
The desktop app must be open and online. Web or mobile sessions can drive it when that is true. Without the desktop app, Claude in Chrome is the path.
Claude in Chrome (generally available)
Claude in Chrome is the extension that works on the page you already have open—with accounts you are already signed into (CRM, inbox, the doc in front of you). As of 26 August 2026 it is generally available on every paid Claude plan. Claude can act autonomously; a safety classifier validates each action first. Anthropic positions it for tools without a connector: internal dashboards, legacy systems, vendor portals. Install from the Chrome Web Store; Enterprise admins manage it in Organization settings and can limit approved domains. It does not run on other Chromium browsers or on mobile yet. The Claude desktop app is still required for local files and other applications.
If you already use Claude in Chrome, it stays your Cowork default; otherwise the built-in browser becomes default once it reaches you. Switch under Settings → Cowork → Preferred browser.
The Softix C⁴ Browser Path (Click–Chrome–Connect–Contain)
Use this four-path playbook before you write a policy or open a build ticket.
| Path | When it fits | What to use | What not to expect |
|---|---|---|---|
| Click | One-off or occasional work on a trusted portal with no API (pull this month’s invoices, research a vendor page, fill a low-risk form) | Claude Cowork built-in browser | Repeatable audit trails, multi-user ownership, or stable data into your systems of record |
| Chrome | Daily work inside an app you already have open and signed into (CRM, inbox, shared doc) | Claude in Chrome | Isolation from your personal tabs and passwords—this is your browser session |
| Connect | Recurring, multi-user, audited workflows that must land in your data model | A real API, MCP server, or custom integration | “Just let the agent scrape it” as a long-term architecture |
| Contain | Banking, email/SSO admin, PHI, payments, payroll, or anything Anthropic itself flags as sensitive | Keep browser agents out unless you have a written exception | Assuming safeguards make high-risk sites safe enough for unsupervised use |
Softix analysis: Click and Chrome are seat-and-policy decisions. Connect is a product decision. Contain is a risk decision. Mixing them—“agent clicks the bank portal every Friday into Sheets”—creates silent operational debt.
Choose fast: high-risk (finance, medical, others’ PII, SSO admin) → Contain (Anthropic strongly advises against both paths for that class of work). Recurring, multi-user, audited, schema-bound → Connect. Already open in Chrome with the right login → Chrome. Throwaway handoff on a trusted site in Claude’s browser → Click.
Built-in browser vs Claude in Chrome (quick comparison)
| Built-in browser (Cowork) | Claude in Chrome | |
|---|---|---|
| Where it runs | Side panel in Claude desktop app | Your Chrome browser via extension |
| Login model | Separate; optional site-by-site import | Uses sessions you already have open |
| Best for | Handing off web tasks while you keep working | Acting on the page in front of you |
| Extension required? | No | Yes |
| Desktop app required? | Yes (open + online) for the built-in browser | Desktop still needed for local files/apps; extension is Chrome-only |
| Org toggle (Team) | On by default as it rolls out | Enabled by default |
| Org toggle (Enterprise) | Off at launch; on by default from 10 Sept 2026 unless turned off | Disabled by default; on by default from 10 Sept 2026 unless turned off |
| Admin path | Organization settings → Cowork → Built-in browser | Organization settings → Claude in Chrome |
| Affects the other? | No—settings are separate; you can enable one, both, or neither | Same |
When both are on, Claude uses Preferred browser. If it is offline and the user asked for a browser generally, Claude continues with the other and says so; if they named one specifically, Claude asks first (Team/Enterprise setup).
Pre–10 September 2026 admin checklist
Owners and Primary Owners: treat this as a control window.
- Set org defaults before they flip. On Enterprise, both browser paths turn on by default on 10 September 2026 unless turned off. Team defaults them on as the built-in browser rolls out. Check Organization settings → Cowork and → Claude in Chrome (admin controls).
- Announce internally. Enterprise users are not notified automatically when you enable either path.
- Keep the toggles separate. Enabling Claude in Chrome does not enable Cowork’s built-in browser, and vice versa. Extension role permissions are separate from Cowork.
- Login-import policy for Click. Leave banking, email, and SSO unchecked unless Legal/Security approve a written exception. Logins inside the built-in browser persist on that machine.
- Chrome pilots: restrictive allowlist first. Expand later. Extension allowlists/blocklists apply when Claude works in Chrome.
- Document Preferred browser. So staff do not improvise mid-task.
- Prompt-injection hygiene. Shared layers: per-site prompts, high-risk blocklists, action checks—they reduce but cannot eliminate risk. Start on trusted sites; stop if behavior looks off (Use Claude in Chrome safely).
- Optional frame: CISA’s Careful Adoption of Agentic AI Services (1 May 2026) is general government guidance—not Claude-specific documentation.
When Claude seats are enough—and when to build
Seats are enough for occasional trusted-portal chores (Click), daily help on an open Chrome tab (Chrome), human-watched outcomes, and no need to land structured data into ERP/CRM on a schedule.
Build a connector or custom app when the portal is fragile or layout-unstable; when there is no usable API but the job is daily and multi-user; when you must stay system of record with audit logs; when compliance needs more than a chat transcript; or when several people must run the same schema-bound job—that is web app or SaaS engineering, often with an MCP or custom API, not a browser path.
Risks and limits
- Prompt injection is non-zero. Hidden instructions in pages or forms can redirect the agent; safeguards help but are not a guarantee.
- Sensitive data is out of scope. Anthropic advises against financial, medical, and others’ personal data on both paths. Claude in Chrome is not available to HIPAA-covered organizations.
- You still own the actions—messages sent, data accessed, purchases.
- Enterprise defaults flip 10 September 2026 if you do nothing.
- Click is not Connect. One good scrape is not a production integration.
90-day actions
Days 1–10: Owner reviews both toggles; write Contain list; announce policy; set Preferred browser guidance; Chrome pilots get a restrictive allowlist.
Days 11–40: Click on two trusted vendor portals only; Chrome on one non-sensitive daily app; log failures. No email, banking, or SSO.
Days 41–90: Promote daily multi-user schema-bound jobs to a Connect brief (API, MCP, or custom software). Keep seats for research and supervised handoffs. Revisit Contain with Security.
FAQ
Is the built-in browser the same as Claude in Chrome?
No. The built-in browser is Claude’s own browser inside the Cowork desktop app. Claude in Chrome is an extension that acts in your Chrome session. Same family of safeguards; different isolation and login models.
Do we have to turn both on?
No. Anthropic documents that you can enable Claude in Chrome, the built-in browser, both, or neither. Settings are separate.
What happens on 10 September 2026?
On Enterprise, both paths turn on by default unless an Owner or Primary Owner turned them off. Team already defaults them on as they roll out. Confirm live org settings.
Should we rip out existing integrations?
No. Browser agents fill gaps where connectors do not exist and help on open tabs. Recurring audited workflows still belong on APIs and apps you control.
What to do next
Treat this as policy and pathing: Click, Chrome, Connect, or Contain—then match the admin toggles before Enterprise defaults move.
If you face a fragile portal, a missing API, or a workflow that needs audit logs and a real data model, that is custom software—not another seat. Softix can map which jobs stay on Claude and which should become a connector or web application. Contact us with your Claude plan (Team vs Enterprise), the portals in play, and whether you need a policy review or a build brief.
Share


