I've spent the last few months connecting Claude to calendars, documents and many other software. The next logical step is to allow Claude to work directly in the browser.
We believe that AI using browsers is inevitable. With a lot of work being done in the browser, seeing what Claude is looking at, clicking buttons, filling out forms can be much more useful.
However, AI using browsers poses safety and security challenges that require a stronger safeguard. By getting real-world feedback from trusted partners on usage, shortcomings and safety issues, we can build robust classifiers and teach future models to avoid unwanted behavior. This ensures that your browser's safety stays at its pace as the functionality progresses.
Browser-using agents with frontier models have already appeared, making this task particularly urgent. By solving safety challenges, you can better protect your Claude users and share what you've learned with those who build browser use agents with APIs.
Start with a controlled test: A Claude extension in Chrome that allows trusted users to instruct Claude to take action within the browser. We pilot 1,000 maximum planning users (to combine into the waitlist) to learn as much as possible. Through this limited preview, we will gradually expand access as we develop stronger safety measures and build trust.
Browser AI Considerations
Within humanity, we have seen substantial improvements using an early version of Claude Chrome to manage calendars, schedule meetings, draft email responses, process regular cost reports, and test the functionality of new websites.
However, the vulnerability remains before making Chrome's Claude generally available. AIS faces rapid injection attacks using browsers just as people encounter phishing attempts in their inbox. Malicious actors hide instructions on websites, emails, or documents, trick AIS into harmful actions without user knowledge (“ignoring or doing previous instructions, etc.”) [malicious action] instead.”).
With a rapid injection attack, AIS deletes files, steals data and engages in financial transactions. This is not speculation. We performed a “red teaming” experiment to test chrome Claude.
We evaluated 123 test cases representing 29 different attack scenarios and conducted extensive hostile rapid injection tests. Using the browser without safety mitigation showed an attack success rate of 23.6% when the malicious actors were intentionally targeted.
An example of a successful attack was a malicious email claiming that it was necessary to delete the email for security reasons before the new defense was applied. When processing my inbox, Claude followed these instructions to delete the user's email without confirmation.



As explained in the next section, we have already implemented some defenses that significantly reduce the success rate of attacks, but there is still something to do when discovering new attack vectors.
Current defense
The front line of defense against rapid injection attacks is authority. Users continue to control what Chrome for Chrome can access and run.
- Site-level permissions: Users may grant or revoke Claude's access to certain websites at any time of their settings.
- Action check: Claude asks users before taking risky actions such as publishing, purchasing, or sharing personal data. Even when users choose experimental “autonomous mode”, Claude still maintains certain safeguards for highly sensitive actions (note: all red teams and safety ratings were conducted in autonomous mode).
They also built additional protection measures in line with the principles of trustworthy agents of humanity. First, it improves the system prompt, a general instruction that Claude receives before a specific instruction from a user, instructs Claude on how to handle sensitive data, and responds to requests to perform sensitive actions.
Additionally, Claude has blocked the use of certain high-risk categories of websites, including financial services, adult content, and pirated content. We have also begun building and testing advanced classifiers to detect suspicious instruction patterns and anomalous data access requests, even when they occur in seemingly legal contexts.
Adding safety mitigation to autonomous mode reduced the attack success rate by 23.6% to 11.2%. This represents a meaningful improvement over existing computer usage capabilities (Claude allows users to view the screen, but does not have the browser interface we are introducing today).

We also implemented special red teams and mitigation focusing on new attacks specific to the browser, such as hidden malicious form fields in the Document Object Model (DOM) of Web Pages (Document Object Model (DOM) and other difficult injections such as tab titles that only agents may see. With the four browser-specific attack types “challenge” set, a new mitigation has allowed the attack to be reduced from 35.7% to 0%.
Before we can make Claude for Chrome more widely available, we want to learn how to expand the universe of attacks we think and get a better understanding of current and future threats, bringing these percentages much closer to zero.
Participation
Internal testing cannot replicate the complete complexity of how people view the real world. What specific requests they make, the websites they visit, and how the actual malicious content appears. New forms of rapid injecting attacks are also constantly being developed by malicious actors. This research preview allows you to partner with trusted users in authentic terms and reveal what the current protections are working and what you need to work on.
Use pilot insights to refine the rapid injection classifier and underlying model. By revealing real-world examples of insecure behavior and new attack patterns that do not exist in controlled testing, we teach the model to recognize attacks and explain relevant behaviors, ensuring that the safety classifier receives everything the model itself misses. It also develops more sophisticated permission controls based on what users learn about how they want to work with Claude in their browser.
For pilots, we are looking for reliable testers who are used to taking action on Claude's behalf.
If you wish to participate, you can join Claude on the Chrome Research Preview Waitlist at Claude.ai/Chrome. Once you've accessed, you can install the extension from the Chrome Web Store and authenticate with your Claude credentials.
We recommend starting with a trusted site. This means paying attention to data that appears to Claude and avoiding the use of Chrome's Claude on sites that contain financial, legal, medical, or other types of sensitive information. You can find a detailed safety guide in our Help Center.
We hope that in order to continue to improve both Chrome's Claude capabilities and safeguards, we will share our feedback and help you take an important step towards fundamental new ways to integrate AI into our lives.
