The news, 365 days behind — on purpose Delayed live · replaying 2025

One Year Ago.AI

Remember how fast this is.

25AUG2025replayed
one year on
productAnthropic

Anthropic pilots Claude for Chrome, a browser extension that lets AI take actions inside tabs

The controlled pilot gives 1,000 Max plan subscribers an AI agent that can fill forms, manage calendars, and navigate websites, while Anthropic races to contain prompt-injection attacks that succeeded 23.6% of the time in testing.

Anthropic today launches a research preview of Claude for Chrome, a browser extension that lets its AI model see and act inside users’ Chrome tabs from a sidecar panel. The pilot is limited to 1,000 subscribers on the Max plan ($100–$200 per month), with a waitlist for others.

The extension can fill forms, manage calendars, schedule meetings, draft email responses, and navigate websites on the user’s behalf. Anthropic says early internal testing showed meaningful gains on routine tasks, but the company is moving cautiously given the security risks of handing an AI agent direct control of the browser.

Prompt injection attacks—where hidden instructions on websites or emails trick an AI into harmful actions—are the primary concern. In adversarial testing of 123 attack scenarios, unmitigated Claude for Chrome had a 23.6% success rate for deliberate attacks. One example involved a malicious email instructing Claude to delete the user’s inbox messages, which it did without confirmation.

Anthropic says new safety mitigations—improved system prompts, site-level permissions, action confirmations for high-risk steps, and blocks on categories like financial services and adult content—cut the attack success rate to 11.2%. The company acknowledges that internal testing cannot capture the full messiness of real-world browsing, which is why it is starting small. The browser is fast becoming the main battleground for AI agents, with Perplexity’s Comet, Google’s Gemini in Chrome, and Microsoft’s Copilot in Edge all chasing similar capabilities. The question now is whether safety can keep pace.

One year later — open only if you can handle spoilers

Anthropic widened access over the following months: by December 2025 the Chrome extension was in beta for every paid tier — Pro, Max, Team, and Enterprise — and it reached general availability for direct Anthropic subscribers by mid-2026. The browser-agent race only intensified, with rivals shipping their own agentic browsers, even as prompt injection stayed the stubborn, unsolved safety problem Anthropic flagged from the start.

Replay thisPost on XRedditHNLinkedIn

The Weekly Replay · free by email

This week, one year ago — every Sunday.

One email each Sunday: the week's replayed AI news, with the one-year-later annotations included. Written like it's breaking — dated like it isn't.

Free · double opt-in · unsubscribe anytime · privacy