On 26 August 2026, Claude Cowork on the desktop app got its own browser. When a task needs a website, a browser opens in a side panel and Claude navigates it, reads it, clicks and types. No extension. Nothing to install. For anyone running a Cowork rollout inside an Australian business, that removes a step we used to book a separate call for.
What actually shipped
The built-in browser is Claude's browser, not yours. It runs its own profile, separate from the browser on your desktop. Claude does not see your tabs, your bookmarks or your saved passwords. The rollout started on 26 August across Pro, Max and Team plans on macOS, Windows and Linux, with Linux in beta. Enterprise plans had it from day one, managed by admins under Organization settings, then Cowork, then Built-in browser.
It opens on its own when a task involves a website. There is no toggle to find first.
Logins are brought across one site at a time, not in bulk.
Banking, email and single sign-on sites are left out of that import unless you deliberately include them.
If you already run Claude in Chrome, it stays your default. The setting sits under Settings, then Cowork, then Preferred browser.
The browser lives in the desktop app. You can trigger it from the web or your phone, but only while the desktop app is open and online.
The Windows gap that matters here
One detail deserves more attention than the announcement gave it. Logins can be imported from Chrome, Edge or Firefox on macOS. On Windows and Linux, the import works from Firefox only.
That is a problem shaped exactly like the Australian mid-market. The typical Sydney office we walk into runs Windows on Edge or Chrome, with Firefox nowhere on the fleet. For those clients the login import is effectively unavailable, and every site Claude needs to work in has to be signed into by hand inside the built-in browser, once.
This is not fatal. It is a one-off cost per site, and for the portals that actually matter, a supplier ordering system, a council lodgement page, an insurer's broker portal, it is a five minute job each. But it belongs in the onboarding plan rather than being discovered on the day.
Which browser for which job
Both browsers stay. The question is not which product is better. It is whose session the task needs.
Use the built-in browser when the task just needs a browser: gathering research, pulling this month's invoices out of a vendor portal, working through a system that has no connector. You keep working while it runs.
Use Claude in Chrome when the task needs your browser: the CRM record already open, the inbox you are signed into, the document in front of you.
Use neither when a proper connector exists. A connector is faster and steadier than any agent clicking through a web interface, and when it breaks it breaks visibly instead of quietly doing the wrong thing.
How to tell whether you have it yet
The rollout was described as taking roughly a week from 26 August, so most Pro, Max and Team desktop users should have it by now. Two ways to check without guessing:
Open Settings, then Cowork, and look for Preferred browser. If that option exists, the built-in browser has reached your account.
Ask Claude to look something up on a public website. If a browser pane opens inside the app instead of Claude asking you to install anything, it is live.
If neither happens, the usual causes are an out of date desktop app or an Enterprise plan where an admin has not switched it on. Check your app version before assuming the rollout has skipped you.
What it does not remove
The built-in browser carries the same prompt injection exposure as any agent that acts in a browser. Instructions hidden inside a page can try to redirect what Claude does. Anthropic runs the same safeguards it uses for Claude in Chrome, including checks that compare Claude's actions against what was actually asked for, and is direct that these reduce the risk without eliminating it. The advice is to start on sites you trust.
For an Australian business, that means the governance question does not disappear. It changes shape. Under the Privacy Act what matters is which systems an agent can reach, and what personal information it can see or move. A browser isolated from your staff's own sessions is easier to reason about than one sharing them, and that is a real improvement. It is not an answer by itself. The controls that still belong in writing:
Which sites the built-in browser is allowed to act in, starting with ones you trust.
Which logins get imported, and explicitly which do not.
Who reviews an agent's browser actions before they count as done, particularly anything that submits a form or sends a message.
On Enterprise, whether the feature is enabled at all, because that is an admin decision rather than a user one.
What this changes in a Cowork setup
We quote Cowork setup engagements at A$3,500 fixed. A predictable slice of that has always gone to browser access: installing an extension, walking someone through permissions, and in any organisation with real IT discipline, waiting for approval to install a browser extension at all. That last one is not measured in hours. It is measured in weeks of calendar time while a ticket sits in a queue.
The built-in browser removes the install and the approval for Pro, Max and Team plans. On a ten seat rollout, at an office manager rate of roughly A$55 an hour loaded, the direct staff time saved is modest, somewhere around A$300 to A$400. Treat that as illustrative arithmetic rather than a quoted saving. The gain that actually counts is that a rollout no longer stalls behind somebody else's change process.
What replaces it is smaller but not nothing: a first-run session per person to sign into the handful of sites their work touches, and on Windows, no shortcut for doing it.
What not to conclude from this
This is not a reason to drop Claude in Chrome. A good share of useful work happens in sessions the built-in browser deliberately cannot see.
It is not a replacement for connectors. If Xero, Gmail or your CRM has a proper connector, use the connector.
It is not a licence to point an agent at a payment or banking screen. Those sites are excluded from the login import by design, and that design is correct.
It is not a security upgrade on its own. Isolation from your own sessions helps. It does not answer what the agent is allowed to do once it is inside a site.
If you are running Cowork inside an Australian business and want these browser decisions written down once rather than re-argued on every task, that is what a setup engagement is for. Book a time and we will work through which of your systems need a browser at all, and which ones never should.



