KEEP IN MIND

Don't let a browsing AI act freely

Claude for Chrome can read, click and write web pages. At the same time, Anthropic warns of hidden instructions and recommends human control when an action has real consequences.

Publicerad 24 July 2026, 17.04

AI-generated illustration of a browser agent encountering a hidden red instruction before a human approves the next step.

Anthropic has made Claude for Chrome available in beta for Pro, Max, Team and Enterprise users. The extension can read web pages, open tabs, click, type and take screenshots when the user gives it access.

This means that Claude can help with tasks in the browser, but also that every page becomes a possible risk. An attacker can embed a prompt injection, i.e. a hidden instruction that tries to make the AI agent deviate from the user's task.

Anthropic says security filters can detect and stop some such attempts. At the same time, the company writes that no browser agent is immune to prompt injection and that protections do not replace user judgment.

Claude for Chrome has three permission modes. Manual approval pauses before each action. Automatic approval reviews actions in the background but may still miss risks. Skipping all approvals mode lacks the automatic check and should only be used when all content and connections are trusted.

Certain actions are prohibited regardless of location, including purchases, trades, permanent deletions, and changes to security permissions. Claude also requires explicit permission before sensitive information is entered or a permission is granted.

For a Swedish business, a restricted pilot is safer than giving the extension free access. Choose few trusted sites, use harmless test data, and retain manual approval when an error could send a message, change a customer record, or affect an important file.

Därför spelar det roll

A browser agent can move from advice to action. Then a hidden instruction on a page can influence what the agent clicks on or writes. Safe use therefore requires small permissions, clear checkpoints and human review before actions with real consequences.

Det här kan du göra

  1. Start with manual approval and a short list of trusted sites.
  2. Test with harmless data and keep customer details, passwords and payment information out of the pilot.
  3. Always review messages, downloads, and other actions with real consequences before they are implemented.