Rainshadow Systems

Your Browser Can Now Click, Log In, and Buy Things For You — Here's How to Use One Safely

Your Browser Can Now Click, Log In, and Buy Things For You — Here's How to Use One Safely

Web browsers that act on your behalf, clicking buttons, filling in forms, logging into sites, are no longer a lab demo. Anthropic's Claude in Chrome, Microsoft's Copilot Mode in Edge for Business, and Perplexity's Comet are all shipping now, and Claude in Chrome is set to turn on by default for Enterprise customers on September 10, 2026 unless an admin disables it first. Meanwhile OpenAI just retired its own agentic browser, ChatGPT Atlas, folding the idea into ChatGPT itself instead. The technology is consolidating, not going away. If you run a small business, someone on your team is going to try one of these soon, if they have not already, and it is worth understanding what you are actually handing over before that happens.

What agentic browsing actually means

A normal AI chatbot answers questions. An agentic browser takes actions: it reads a page, decides what to click, fills in a form, and moves on to the next step, often across several tabs in a row. That is genuinely useful for repetitive browser work, pulling data from a supplier portal, comparing prices across a handful of sites, or filling out the same web form for ten different accounts.

The catch is that it does this using your logged-in sessions. If you are signed into your bank, your accounting software, or your email when the agent is running, it can see and potentially act on all of it, because from the website's point of view, it is just you clicking around.

The risk that actually matters: prompt injection

The specific danger security researchers keep coming back to is prompt injection: instructions hidden in a web page, email, or document that the AI reads as part of doing its job. Anthropic's own guidance for Claude in Chrome gives a plain example of how this works: a to-do list or email might contain invisible text instructing the agent to retrieve bank statements and share them in a document. The agent cannot always tell the difference between your instructions and text planted by someone else on a page it is reading, which is why Anthropic recommends caution rather than blind trust (Anthropic's Claude in Chrome safety guidance).

Anthropic is direct about this: safety classifiers screen for these attacks, but the risk is not zero. No vendor currently claims a complete fix for prompt injection. That is not a reason to avoid these tools, it is a reason to control what they are allowed to touch.

A safety checklist before you turn one loose on your business

You do not need to be a security expert to use an agentic browser responsibly. Treat it the way you would treat a new hire on their first day: useful, but not handed the keys to everything at once.

  • Keep it out of your everyday, logged-in browser profile. Use a separate Chrome profile for agent tasks that is not signed into your bank, payroll, or accounting software. If the agent never has that session open, it cannot act on it.
  • Start in manual-approve mode. Claude in Chrome offers manual approval, automatic approval with background safety checks, and a mode that skips approvals entirely for fully trusted tasks. Start with manual approval so you see every action before it happens, and only relax that once you trust the specific, narrow task you have given it (Claude in Chrome permissions guide).
  • Do not rely on it for money, contracts, or customer data by default. Some vendors hard-block certain actions outright. Claude, for example, will not complete financial transactions, create accounts, or handle credit card or ID data under any permission setting, but assume other tools are more permissive unless you have checked.
  • Use an allowlist if you are on a business plan. Team and Enterprise Claude plans let an admin restrict the extension to a specific list of approved sites and block everything else. If you are rolling this out for more than just yourself, set the allowlist before anyone else on the team turns it on (Claude in Chrome admin controls).
  • Fill in credentials with a password manager, not the chat window. Where a password-manager integration exists, use it, so login details are filled directly and never pass through the AI's context at all.
  • Watch for it doing something you did not ask for. Unexpected navigation, a task that suddenly veers into a different site, or a request to enter sensitive information you were not expecting are all reasons to stop and check what page it is actually reading.

What to do this week

You do not need a policy document to get started safely. Pick one low-stakes, repetitive browser task, pulling the same report from a supplier site every week, or checking a handful of competitor prices, and try it in manual-approve mode on a browser profile that is not logged into anything sensitive. See what the agent actually does before you decide what else it is allowed to touch. If you are the one setting this up for a team, decide on the site allowlist and the default permission level before you flip the switch for everyone else, not after.

Agentic browsers are a real productivity tool, and they are only going to get more capable. The businesses that get the most out of them safely will be the ones that start narrow, watch closely, and expand access on purpose rather than by default.

← All posts Work with us