THE AI MINDSET

Good day, AI leaders.

Usually, The AI Mindset brings you three developments each week.

Today, I’m doing something slightly different.

One story. One issue worth looking at properly.

AI assistants are rapidly becoming AI agents. They are moving beyond answering questions and gaining access to browsers, email, documents, local files, connected applications and business systems.

And increasingly, they can do more than read.

They can search, create, update, send, click, invoke tools and execute actions.

That changes the governance question.

It is no longer enough to ask whether an AI model gives reliable answers. Organisations also need to understand what the agent can access, what authority it has, what happens when something tries to manipulate it, and whether the controls around it actually work.

A warning I encountered while setting up Claude in Chrome this week illustrates the problem remarkably well. But the bigger story is Cowork, and what happens when an AI agent is given access to the browser and the local working environment..So this week, rather than three stories, we’re going deeper on one.

Let’s get into it.

In today’s AI Mindset

  • Cowork Can Read, Click, Type and Act. The Warning Screen Is Only the Start.

LATEST DEVELOPMENTS

AI REGULATION
🌎 Cowork Can Read, Click, Type and Act. The Warning Screen Is Only the Start.

Claude in Chrome shows three warnings before you start. The bigger story is Cowork: the same agent can now browse, use connectors and, on supported desktop setups, work with apps and files on your computer.

Category: AI Governance, Risks & Compliance | Reading time: 9 minutes:

What changed: Anthropic’s current guidance says the Cowork side panel in Chrome starts in “Automatically approve” mode. Claude keeps working, screens each action for risks such as prompt injection or data exfiltration, and pauses when it decides approval is needed. Anthropic says its current Chrome configuration reduced known attack success below 0.08% in internal testing, while also warning that no defence is perfect and new attacks may appear.

How it affects you: Cowork is no longer only a chat window. It can use the browser, connectors and, with computer use enabled, interact with local applications and files. Computer use relies on screenshots, so Claude can see information visible in an approved app, including personal or sensitive data. Anthropic explicitly says safeguards can fail and recommends closer supervision for tasks involving real consequences. The important question is therefore not whether Cowork is secure in general, but whether the permissions granted in your environment are proportionate to the task.

What to do: Check the actual permission mode on every machine and browser using Cowork. Review which apps, sites, connectors and accounts it can reach. For sensitive work, switch to Manual approval and restrict access rather than assuming “human in the loop” exists because a policy says so. On Team and Enterprise, administrators can restrict Auto mode and browser access.

Key takeaway: The risk is not simply that Cowork may answer badly. It is that an agent with enough privilege can act badly. Once AI can see, click, type, open files and use connected systems, governance has to move from written permissions to tested boundaries.

Most firms cannot say which of their AI systems can now take actions rather than answer questions. The SAFE™ AI Readiness Assessment scores you across ten governance domains in under ten minutes..

Until next week