Anthropic has made "Claude in Chrome" generally available as of August 26, removing the requirement for user approval on every browser action. The Chrome extension now lets the AI assistant autonomously enter text, click links, navigate pages, and fill out forms while maintaining the user's logged-in state. All paid Claude plans are eligible, and the company reports its latest security evaluation held prompt injection attack success rates to 0-0.3%.
Claude in Chrome previously required confirmation for each action, which slowed workflows. The shift to autonomous execution means the AI can now access tools that lack native Claude integration, such as internal dashboards, legacy systems, and supplier portals. Enterprise customers get management features including domain restrictions and organizational usage controls.
Three-layer defense against prompt injection
Browser-operating AI agents face a known security risk called prompt injection, where malicious instructions hidden in web pages or emails hijack the AI's behavior without the user's knowledge. During Anthropic's 2025 pilot launch, 23.6% of attacks succeeded when no defenses were in place.
The company now combines three measures. First, it trains models on an attack library built from internal automated attack systems, external red teams, and real-world monitoring. Each successful attack against a current model is added to the library and used to improve subsequent models.
Second, "probes" inspect web page and email content that Claude reads, detecting signs of prompt injection. When a potential attack is detected, the probe warns Claude, which asks the user for confirmation before proceeding if necessary. Third, classifiers verify actions immediately before execution, checking whether navigation or text entry matches the original request. Safe actions are automatically approved, though users can change settings to retain manual approval.
In Anthropic's latest evaluation, attack success rates with probes and classifiers combined were 0% for Claude Sonnet 5, Claude Opus 5, and Claude Mythos 5, and 0.3% for Claude Fable 5. The company said all successful attacks involved low-severity scenarios and that it will continue investing in automated attack discovery, red team exercises, and classifier strengthening with each model release.
Usage limit change draws criticism
Separately, Anthropic faces pushback over Claude Code usage limits. The company said that starting September 14, it will permanently increase standard weekly usage limits by 25% on Pro, Max, Team, and seat-based Enterprise plans. But the temporary 50% increase that has been in effect will end, which amounts to a roughly 17% reduction from current levels.
The temporary increase was first announced on May 14 and was originally scheduled to end on July 13, but was repeatedly extended. Users have called the change "wordplay," pointing out the effective reduction despite the permanent increase framing.
Anthropic's defense improvements reflect roughly a year of work since the pilot launch. The company retired its original evaluation suite because attacks against the latest models now fail even without defense mechanisms, and now measures robustness using more powerful attacks devised by professional red teams.
For operations professionals, the practical takeaway is that AI agents can now handle browser-based workflows without constant check-ins - but the security model depends on the combination of probes and classifiers, not the model alone. Teams evaluating autonomous tools should verify which defenses are active in their deployment and whether manual approval remains available for sensitive domains. The usage limit change also matters for teams running Claude Code at scale: the effective reduction from current levels may require re-budgeting for peak workloads.
Your membership also unlocks: