Claude in Chrome hits GA on every paid plan, with autonomous actions
The browser agent now acts without approving each step, and logs 0% prompt-injection success on Sonnet 5 and Opus 5. Plus a thinking dial for Copilot.

Copy markdown
Autonomous actions, no click-by-click approval
Claude in Chrome is now GA on every paid Claude plan, not just the $200/mo Max tier. Flip on auto-approve and it reads and types text, clicks links, navigates pages, and fills forms without asking each time; a classifier checks every action against your original request, and you can keep manual approval or, on Enterprise, restrict it to allowlisted domains.
0% prompt-injection breaks on Sonnet 5 and Opus 5
Against attacks written by professional red-teamers, with probes plus the action classifier, Sonnet 5 and Opus 5 posted a 0% attack success rate — Fable 5 hit 0.3% and older Opus 4.5 16.7% — and every successful break was low-severity. That's the number that makes handing an agent your logged-in tabs defensible.
What you can wire up this weekend
It touches only sessions you're already signed into and pauses on financial or work-critical steps, but that still covers pulling numbers from analytics dashboards, tidying Google Drive, drafting CRM logs, and bulk email triage. It connects to Claude Code, so your dev loop can drive a real browser to test and iterate.
The catch: Chrome-only, desktop-only, your-tabs-only
No other Chromium browsers and no mobile yet, and it can't open new authenticated sessions on its own — it acts only where you're already logged in. Anthropic explicitly advises against pointing it at banking or health records.
Elsewhere: VS 2026 adds a Copilot 'thinking effort' dial
Visual Studio's August update lets you dial Copilot's reasoning effort up or down per task and work across multiple models and branches in one flow — more control over the cost-versus-depth tradeoff without leaving the IDE.