My work jumps between screens all day. I start something on the laptop, walk into a meeting, and want to continue on the train home. Claude Code and Cowork already handle that, and I wrote earlier about which of those surfaces is meant for what. The browser was the exception. Whatever you did in the Chrome side panel stayed in that one window on that one machine, and it was gone the moment you closed it.
Not since August 12. The side panel now runs the same session as everything else.
What was announced
Anthropic posted it in three messages on X. The side panel of the Chrome extension now runs a Claude Cowork session, the same kind of session you get in the desktop app, on the web, and on mobile. What that means in practice is spelled out more precisely in the support article than in the announcement itself.
Your conversations are saved. Every side panel session shows up in your history like any other Cowork session.
Sessions move with you. Start in a tab, pick it up on the web, in the desktop app, or on your phone. The phrasing in the documentation is the heart of the news: sessions live with your account rather than with the machine you started on.
Your skills, plugins, and connectors work there too. They behave the way they do in Cowork on desktop, and a skill you save in the side panel runs from any surface.
Availability: Max and Team today, Pro over the coming weeks. On Enterprise the side panel only becomes a Cowork session once your admin enables Cowork in the cloud; until then that group gets the classic experience. The extension itself is available on every paid plan, Pro included, but the side panel is still in beta.
What quietly goes away
Here is the part that sits in the support article rather than the announcement.
The classic side panel had a record button. You hit record, walked through the steps yourself once, stopped recording, and saved the whole thing as a shortcut. For the dull repeat jobs on a single site, the same export from the same dashboard every week, that was the most useful thing in there.
Recording is not available when the side panel runs as a Cowork session.
| Classic side panel | Cowork side panel | |
|---|---|---|
| Conversation saved | no | yes, in your history |
| Continue on another device | no | yes, session lives with your account |
| Skills, plugins, connectors | no | yes, same as desktop |
| Record a workflow | yes | no |
| Who gets it | Enterprise without Cowork | Max and Team now, Pro to follow |
That is a real trade and not a footnote. Anyone whose work lived in recorded shortcuts gains portability and gives up the recording. Anthropic does not say it will return.
The mechanics: why this is more than syncing
The word you would expect is sync, and syncing is exactly what this is not. No conversation history gets copied from your laptop to your phone. The session was never on your device to begin with.
A Cowork session lives server side, attached to your account. What the extension, the desktop app, and your phone do is open a window onto it. That is why nothing has to travel when you switch devices: the only thing that changes is which window is looking.
It also explains why your skills come along. They belong to the same account rather than to an install, so a skill you save in the side panel runs just as well in Cowork on your laptop afterward. It is the same move Cowork itself made when my sessions left my laptop for the cloud; the browser is the last surface to join.
The price of that design is that browser work is no longer local. What the side panel reads off your screen feeds a session that lives elsewhere and can be reopened from any device later, including the phone in your coat pocket.
The numbers that belong here
The announcement itself carries no numbers at all. The question underneath it, how safe an agent in your browser really is, does have them, in an Anthropic research post dated November 24, 2025.
The setup: an internally built “Best-of-N” attacker that combines known prompt injection techniques and gets a hundred attempts per environment. The resulting figure is called attack success rate, the share of attacks that land, and for the extension version shipping at that time it was 1 percent.
Read the paragraph below it too, because it is more interesting than the percentage. Anthropic writes that 1 percent still represents meaningful risk, that no browser agent is immune to prompt injection, and that they publish these results to show progress rather than to claim the problem is solved. The support article is just as blunt: the risk is not zero, and a successful attack could lead to data exfiltration.
Two things to keep in mind. This is an internal measurement with an internally built attacker, not an outside audit. And it dates from November 2025, so it says nothing about the version that shipped this week. On top of that, a side panel tied to your account rather than your laptop changes what a successful attack is worth: the same session can now be opened from more places.
What I do myself
I do not use the side panel, and this does not change that. My browser work runs through Claude Code, which drives the extension as a tool: the instruction then lives in the same session as the rest of my work, and the transcript shows me what got clicked.
What I will use is the handoff to mobile, for reading rather than acting. Starting a session on the laptop and checking the result while out is exactly the shape I trust here.
One setting I change immediately. The side panel starts in “Automatically approve,” where Claude keeps working and only pauses when the safety check flags something. Pick a different mode and the panel remembers your choice for future sessions. I set it back to asking before acting, and on financial sites or anything with personal data the panel stays closed. Claude takes screenshots of your active tab, so everything visible there has been read.
The caveat
The default shifts from asking to proceeding. The side panel opens in automatic approval, with a safety classifier as the net. That is a defensible call for convenience, and it does mean the quietest setting now requires an action from you instead of being where you start. Anyone who never changes it has silently agreed to an agent that runs until a classifier stops it.
Responsibility lands on whoever opens the panel, not on whoever built it. Anthropic is straightforward about the risks: start with trusted sites, avoid financial transactions, watch what is on screen. Except that warning lives in a support article, while the action that counts is popping open a panel next to the page you already had open. The gap in effort between those two is the whole problem.
What drains away is the local character of browser work. What you did in the browser used to stay in the browser. Now it belongs to a session attached to your account, with your history and your skills around it. You get portability in return, and you give up the fact that closing a tab used to mean something. The recorded workflow is the clearest evidence of that trade: it was the one thing that happened locally on a single machine, and it is gone.
Frequently asked questions
Does this work on my Pro plan yet?
Not fully. Anthropic names Max and Team as of August 12 and says Pro follows over the coming weeks. You can install the extension on any paid plan; what is rolling out here is only the side panel running as a Cowork session. No date was given, so the rollout may reach you later than it reaches a colleague.
Can I still record a workflow?
Only in the classic side panel. According to the support article, recording is not available when the side panel runs as a Cowork session. If you rely on recorded shortcuts for recurring jobs, that is the reason to hold off on celebrating. Nothing has been announced about a replacement.
Does Claude see everything in my browser?
Everything visible in the active tab while the panel is open. Claude takes screenshots of it to understand the page, so any personal data or confidential document on screen at that moment has been read. Adult sites and known pirated content sites are blocked, and Claude asks permission before accessing financial sites.
What happens if a page contains hidden instructions?
That depends on the classifiers. Two of them run: one screening incoming content for injection attempts, and one checking every action before it executes. Anything flagged is blocked or handed to you for approval. Anthropic measures a 1 percent success rate for its own attacker and says in the same breath that this is not zero.
Is this the same as browser access from Claude Code?
No. That is the other side of the same extension: from Claude Code or Cowork you give an instruction and Claude opens Chrome to carry it out. The side panel runs the other direction, starting in the browser with the page you already had open. As of this week both end up in the same kind of session.
Sources
- Claude (@claudeai), announcement plus two follow-up posts on X, August 12, 2026 — x.com/claudeai
- Anthropic, “Get started with Claude in Chrome,” support article, accessed August 13, 2026 — support.claude.com
- Anthropic, “Use Claude in Chrome safely,” support article on risks, classifiers, and blocked sites, accessed August 13, 2026 — support.claude.com
- Anthropic, “Mitigating the risk of prompt injections in browser use,” research post with the ASR measurement, November 24, 2025 — anthropic.com/news
Checked on August 13, 2026. I read the three posts on X myself; I could not watch or transcribe the video attached to the announcement, so anything stated there and nowhere else is missing from this piece. Everything about sessions, skills, plan availability, and the missing recording feature comes from Anthropic’s own support articles, which I read; those are the primary source here and they are more specific than the announcement. The 1 percent figure comes from a research post dated November 2025 and describes the extension version of that moment, not the one that shipped this week; it is also an internal measurement with an internally built attacker and has not been audited by an outside party. That the side panel starts in automatic approval and remembers your choice is stated in the support article; I could not verify it on a Pro account, since the rollout has not reached that plan. Whether recording returns to the Cowork side panel is unknown; Anthropic says nothing about it.
