
Anthropic updated its Chrome extension so that Claude, its AI assistant, now runs as a full "Cowork" session inside the browser sidebar. It can see the page you are on, carry conversations across from the desktop and phone apps, and use whatever tools and connectors you have set up. It is out for Max and Team subscribers, with Pro users to follow.
Here is the part that matters for a small business. Anthropic's own pitch is that plenty of the software you use every day cannot be plugged into an AI assistant directly: internal dashboards, older systems, vendor portals. The browser extension gets around that by simply operating those tools the way a person would, through the screen. That includes your website's admin area, your booking system, your invoicing tool, your supplier portal.
So the practical change is that any staff member with this extension installed can point an AI at your business systems without anyone granting it access, buying an integration, or telling you. There is no setup to approve. It is just a browser add-on looking at whatever is on screen.
Anthropic names the main risk itself: prompt injection. That means text hidden on a web page that is written to give the AI instructions, which the AI then follows as though you had typed them. If your assistant is logged into your site's admin and reads a page containing hidden instructions, the concern is that it acts on them. Anthropic has extended its automatic checking to the browser agent, but it does not describe the risk as solved.
None of this breaks your website. It changes who and what might be logged into it.
What to do:
- Ask whether anyone on your team is using a browser AI extension while logged into your site, booking system or payment tools. Not to ban it, just to know.
- Check that staff logins are separate and limited to what each person needs. If an AI agent goes wrong inside an account, the damage stops at that account's permissions.
- Next time you speak to your developer, ask what your admin logins can actually do, and whether any of them could delete or expose something they do not need to touch.
Reported by:


