PaPoo
cover

Claude’s browser split feels like a practical fix, not a flashy one

What jumped out at me is that Anthropic is finally admitting the obvious: “browser automation” is not one problem, it’s two. Sometimes you want Claude to act inside your already-signed-in Chrome session. Sometimes you want it quarantined in its own sandbox, doing tedious web chores while you keep working. That distinction feels right.

I’m more interested in that than in the usual “AI can browse the web now” framing. The built-in browser inside Claude Desktop sounds like the cleaner option for task handoff. No extension dependency, no need to hand over your own browser state, and, at least in theory, a lower-friction setup for the kind of thing people actually ask an agent to do: gather documents, pull invoices, click through portals. That is the boring stuff, and boring stuff is where these agents either earn trust or collapse under weird edge cases.

The part I’d want to test first is the login/import story. The article says Claude’s browser is isolated from your tabs, bookmarks, and passwords, but can import login info from specific browsers, with bank, mail, and SSO sites excluded unless you explicitly include them. That sounds sensible. It also sounds like the sort of policy that will be annoyingly porous in practice, because “explicitly include them” is doing a lot of work. I’d want to know how much control users really get, and how easy it is to accidentally widen the blast radius.

I also think Anthropic is trying to draw a neat product boundary between Claude in Chrome and the built-in browser, but the boundary is a little blurry. Their suggested split makes sense on paper: use Chrome for the page you’re already on, use the internal browser when you want to hand off a task and move on. In real life, people will probably use whichever one is already open and “good enough.” That’s fine, but it means the UX argument matters less than the reliability and safety story.

And that’s where the prompt injection warning is the real headline, even if it isn’t the shiny one. Anthropic is still saying, in effect, “yes, the risk remains.” That’s honest. It also tells you these browser agents are not something I’d let loose on random sites without watching them. The built-in browser may be more convenient, but convenience does not make web contamination problems disappear.

The one detail that makes me cautiously optimistic is the move toward autonomous operation for “safe” actions in Claude in Chrome, with a classifier checking safety and instruction match before execution. That’s the direction these tools need to go if they’re ever going to feel less like scripted demos. But I’d still want hard evidence that the classifier isn’t just a polite gatekeeper with a nice UI.

If I were building with Claude, I’d probably try the built-in browser for low-risk, repetitive web work first. Not because it sounds magical. Because it sounds less annoying.


Reference: 「Claude Cowork」に内蔵ブラウザー、「Claude in Chrome」も全プランで一般提供/エージェントのWeb操作に2つの選択肢

同じ著者の記事