• Deutsch
  • English
  • Claude is gaining the ability to perform tasks directly in a browser and on connected devices. This moves Artificial Intelligence (AI) beyond answering questions toward acting as an agent, meaning a system that completes multistep tasks with some independence. The change affects individual users and organizations alike because it makes Claude more useful while giving errors or manipulated instructions more serious consequences.

    What Claude can now do directly

    Anthropic is adding a dedicated browser to its desktop app, according to a report on Claude Cowork. When a task requires a website, the browser opens in a side panel. Claude can visit pages, read their contents, click buttons, and enter text.

    One everyday example is filling out an online form. At work, Claude could collect figures from a web-based dashboard even when the portal lacks an application programming interface, which is a designated digital connection for other software. A request such as “Collect the monthly figures from this portal” can therefore become an executed task rather than a set of instructions for you to follow.

    The built-in browser remains separate from your personal browser. Claude cannot see your existing tabs, bookmarks, or saved passwords. According to the report, you can transfer logins individually from Chrome, Edge, or Firefox, while banking and email sites are excluded. Anthropic still directs you to its Chrome extension when you want Claude to work with a page that you already have open and are signed into.

    The browser is due to become available during the week of the report for Pro, Max, and Team plans, as well as enterprise customers. The source provides no specific prices. It also does not say whether every feature will launch at the same time in all countries and languages.

    Why the next step matters

    Browser access is only one part of this expansion. Anthropic also wants agents to interact with laboratory and manufacturing equipment through the Model Hardware Standard (MHS), a shared specification for controlling programmable devices. The company’s MHS research preview initially targets a group of scientific laboratories and advanced manufacturers.

    MHS uses standardized drivers, meaning software that translates between a computer and a device. This is intended to make microscopes, liquid handlers, and robotic arms discoverable and controllable through a shared structure. Anthropic says the standard is not limited to Claude and can be accessed by other agent systems through standard protocols.

    Anthropic gives the example of an AI system adjusting a laser, checking the result with a camera, and repeating the process until calibration is complete. Another example has Claude focus a microscope, analyze its images, identify an area that deserves closer inspection, and reposition the microscope. Ars Technica notes that a common machine interface does not inherently require AI and can also be controlled through conventional commands.

    According to Anthropic, MHS could reduce the work needed to integrate different devices from weeks or months to hours or minutes. That estimate comes from the provider and has not been independently verified. The preview is also meant to support the development of safety evaluations and best practices before the standard is released as open-source software.

    Pros and Cons of autonomous Claude agents

    Pros:

    • Less manual work – Claude can take over repetitive clicking, reading, and data-entry tasks in web portals.
    • Access to older portals – The browser can work with sites that do not provide an application programming interface.
    • A shared device language – MHS is intended to reduce the need for custom links between individual laboratory or manufacturing devices.
    • Multistep workflows – An agent can inspect results, adjust parameters, and, according to Anthropic, sometimes recover from hardware errors.

    Cons:

    • Manipulated content – Websites or documentation can contain hidden instructions that an agent mistakenly follows.
    • Greater impact – A poor text suggestion is easier to correct than an executed command or a changed hardware setting.
    • Incomplete safeguards – Security filters may miss attacks and can, in the worst case, block a later cleanup attempt.
    • Unclear accountability – The more independently a system operates, the harder it becomes to oversee long or unattended workflows.

    Which safeguards are essential

    The central technical risk is prompt injection, meaning a malicious instruction embedded in a website or file that redirects an agent from its intended task. Anthropic therefore recommends limiting the Cowork browser to trusted websites. Separating it from your personal browser and importing logins one site at a time reduces the amount of exposed data, but it does not remove the underlying problem.

    A report on automatically installed code illustrates the risk. Researchers found machine-readable documentation files on more than 100 websites that referred to unregistered software packages or domain names. After registering some of those unclaimed names, the researchers received connections from several corporate networks; recorded process chains indicated that agents including Claude, OpenAI’s Codex, and Hermes were involved.

    The investigation exposes a software supply-chain risk: an agent may treat technical documentation as authoritative and execute installation instructions found inside it. According to the report, at least one misconfigured site was already directing visitors toward live malware. Anthropic, OpenAI, and Nous Research had not responded to Ars Technica’s requests for comment by publication time.

    Automatic safety modes do not provide a guarantee either. An attack on Claude Code summarized by Simon Willison allegedly succeeded in 80 percent of attempts, according to security researcher Johann Rehberger. A prepared archive caused the agent to run local code. The success rate is the researcher’s claim and was not independently verified in the supplied sources.

    The especially troubling detail was that the automatic protection mode allowed the malicious process to be created in some runs but then blocked Claude’s attempt to stop it. Willison therefore recommends a sandbox, an isolated environment for running software, along with restricted outbound network access, monitoring, and no access to home directories, security keys, or cloud credentials.

    Step 1: Define the task and its limits

    1. Specify as narrowly as possible which website, data, and action the agent may use.
    2. Avoid broad assignments that let the agent independently choose additional sources or software installations.

    Step 2: Grant minimal access

    1. Transfer only the login for the site that the Cowork browser actually needs.
    2. Keep personal accounts, confidential folders, and unnecessary credentials outside the agent’s environment.

    Step 3: Review consequential actions

    1. Inspect forms, downloaded files, and proposed commands before final approval.
    2. Do not leave sensitive or difficult-to-reverse workflows unattended.

    Step 4: Monitor the environment

    1. Use a separate, monitored environment for agent tasks that carry significant risk.
    2. Limit network access and maintain a record of the actions the agent performs.

    What this means for you and Switzerland

    If you are a beginner, start with a task that is easy to verify and reverse. Claude might collect figures from a nonconfidential dashboard or prepare a form that you review completely before submission. This lets you judge how reliably the browser performs without immediately exposing highly sensitive accounts.

    If you are an advanced user, you can get more value by keeping tasks, accounts, and working environments strictly separated. In an organization, that means working with the responsible information technology team to define which websites, networks, and data an agent may reach. The documented attacks indicate that a built-in safety mode alone is not enough for unattended workflows.

    Several practical questions remain unanswered for Switzerland. The sources do not specify dedicated Swiss availability, support for the country’s languages, or whether data can be processed in Switzerland. Before deployment, organizations in education, research, and the workplace therefore need to use the actual product and contract settings to determine which data Claude may access and which actions it may perform.

    Claude’s dedicated browser and MHS make the system considerably more capable of taking action: the agent can explain, but also click, type, measure, and adjust equipment. That can reduce work in clearly bounded processes, while shifting some of the risk from incorrect answers to incorrect actions. The main unresolved issue is whether safeguards can reliably detect manipulated content before an agent gains access to valuable data, corporate networks, or physical equipment.

    Sources

    AI-FunghiAI-Funghi

    © 2024 - 2026 ai-funghi.com | All Rights Reserved | Impressum | Datenschutz