Anthropic does not have a single agent product with a single launch date. What it has is a direction, pursued in public for almost two years: teach Claude to operate software, then wrap that ability in products people will trust with real work. The thread starts with a computer-use public beta on 22 October 2024, when Claude 3.5 Sonnet scored 14.9% on the OSWorld benchmark’s screenshot-only category and Anthropic itself called the feature “cumbersome and error-prone.” By 30 September 2026 the picture is very different. The computer-use tool has a production version on the API that needs no beta header. Claude in Chrome became generally available on every paid plan on 26 August 2026. On 16 September Anthropic folded Cowork, its desktop agent for non-developers, into the main Claude app. Two new models followed within a week: Claude Opus 5.5 on 22 September and Claude Sonnet 5.5 on 28 September.
The significance is less any one release than the shape of the stack. Anthropic now owns a protocol (MCP, since donated to the Linux Foundation), a developer agent (Claude Code), a framework and hosted runtime (the Agent SDK and Managed Agents), a browser agent, a desktop agent and a tiered model family that includes restricted Mythos models. That stack has also produced documented failures: a seven-week quality regression in Claude Code, a prompt injection that exfiltrated files from Cowork days after launch, and misuse of Claude Code in state-linked cyber operations. This article looks at both sides.
From chat window to working agent: why the Claude AI agent matters
AI products have been slowly moving initiative from the person to the software. Chatbots answered questions. Copilots suggested the next line while the human stayed in charge. Task agents ran short sequences of tool calls. Computer-use agents read the screen and moved a cursor through software never designed for machines. The newest step is the persistent agent, which keeps working after the user closes the laptop.
Anthropic’s route through this sequence started with developers. Its agentic capabilities appeared as API features, a command-line tool and an open protocol long before they reached a friendly desktop window. As a result, Claude’s agent features are built from composable pieces (tools, skills, connectors, sandboxes, approval modes) exposed to developers first and packaged for everyone else later.
For product teams, the question is no longer whether an AI agent can operate software. It can, imperfectly. The question is how it chooses between the clean route (an API or connector) and the messy route (clicking through an interface), and what a product should look like when some of its users are machines.
What Anthropic has actually shipped: the Claude agent stack in September 2026
Because this is a direction rather than one product, it is clearest by layer, each labelled by status on 30 September 2026.
Computer use on the API (released). Public beta from 22 October 2024. Current documentation lists a production toolset, computer_toolset_20260801, that needs no beta header and supports Fable 5 and 5.1, Mythos 5 and 5.1, Opus 4.8, 5 and 5.5, and Sonnet 5 and 5.5. It gives Claude screenshots, mouse and keyboard control inside an environment the developer provides.
Model Context Protocol (released, open standard). Introduced on 25 November 2024. On 9 December 2025 Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation, co-founded with Block and OpenAI, when the project reported 97 million monthly SDK downloads and about 10,000 active servers.
Claude Code (released). Research preview in February 2025, generally available on 22 May 2025 with IDE extensions and GitHub Actions. A sandboxed web version followed on 20 October 2025, and agent teams arrived as a research preview with Opus 4.6 on 5 February 2026. In February 2026 Anthropic put Claude Code’s run-rate revenue above $2.5 billion.
Claude Agent SDK (released) and Managed Agents (public beta). The Claude Code SDK became the Agent SDK on 29 September 2025. Managed Agents launched on 8 April 2026 as hosted infrastructure for long-running agents, at token rates plus $0.08 per session-hour.
Claude in Chrome (released). A pilot with 1,000 Max subscribers began on 25 August 2025, widened to all Max users in November and to Pro, Team and Enterprise on 18 December 2025. It became generally available on all paid plans on 26 August 2026, in Chrome only.
Cowork, now part of Claude (released, with beta pieces). Cowork launched as a macOS research preview for Max on 12 January 2026 and became generally available on macOS and Windows for all paid plans on 9 April 2026. Desktop computer use arrived as a research preview for Pro and Max on macOS and Windows on 23 March 2026. On 16 September 2026 Anthropic announced that Cowork and chat are “now one Claude,” rolling out to Pro and Max first, alongside Claude Docs and Claude Slides in beta. The help centre says computer use is in beta for Pro and Max and needs the desktop app open, and that from 6 October 2026 new Pro and Max tasks will run only in the cloud.
The model tiers (released and restricted). Fable 5 launched on 9 June 2026 as a safeguarded, generally available Mythos-class model (access was suspended from 12 June under a US export control directive and restored on 1 July), with Mythos 5 restricted to vetted partners. Fable 5.1 and Mythos 5.1 followed on 1 September at $10 and $50 per million input and output tokens. Opus 5 (24 July) cost $5 and $25; Opus 5.5 (22 September) costs $4 and $20; Sonnet 5.5 (28 September) costs $2 and $10. Mythos 5.1 is limited to US organisations in Anthropic’s verification programmes.
Plans (released). Pro is $20 a month, Max starts at $100, and Team seats run from $20 to $125. Usage runs on rolling five-hour windows, with weekly caps on paid plans.
Why this direction matters now
Three things changed between the 2024 beta and today.
First, capability moved from novelty to usable. Anthropic reports Opus 5.5 at 81.8% and Sonnet 5.5 at 80.1% on OSWorld 2.1 with partial credit. These are vendor-reported numbers on a newer version of the benchmark, so they cannot be compared directly with the 14.9% from 2024. For reference, Sonnet 4.5 reported 61.4% on the earlier OSWorld in September 2025. None of these scores has been independently replicated in production settings.
Second, the agent is no longer confined to developers. The September merge removes the choice between “chat” and “agent” entirely. Anthropic’s stated reason was that users “told us the frustrating part was deciding where a task belonged.” This suggests the company now sees agentic execution as the default mode of the assistant, not a power-user feature.
Third, cost is falling. Opus 5.5 is priced 20% below Opus 5 per token, and Anthropic says it costs about 40% less on typical workloads. Agents consume far more tokens than chats, so this matters.
The product appears designed to capture “delegated knowledge work,” not just coding. Claude Code showed developers would hand over multi-hour tasks. Cowork, Chrome and the merged app look like an attempt to carry that behaviour to analysts, lawyers and operations staff who live in browsers and spreadsheets.
How the Claude AI agent works
The agent loop in plain language
A Claude agent session is a cycle. The user states an outcome. Claude plans, picks a tool, runs it, reads the result and decides the next step, until the task is done, a limit is hit or a human decision is needed. Anthropic’s help page describes Claude breaking work into subtasks and coordinating “parallel workstreams” while the user can steer mid-task.
Three ways to reach software
The key design choice is the order in which Claude reaches an application. When Anthropic introduced desktop control on 23 March 2026, it described a hierarchy: a connector first (Slack or Google Calendar through MCP), then the browser through Claude in Chrome, and direct screen control only after asking permission. A connector call is fast, cheap and structured. Screen control is slow and costly in image tokens; the documentation warns that computer use latency “might be too slow compared to regular human-directed computer actions” and that Claude “might make mistakes or hallucinate when outputting specific coordinates.”
For developers, computer use is a tool definition. The production toolset adds about 4,500 input tokens before any screenshots, and the documentation advises keeping no more than 20 images per request. The developer supplies the virtual machine and executes the clicks Claude requests.
Where the work runs
Location is now a product decision. Claude Code runs in a terminal or in Anthropic’s cloud. Cowork first ran in a Linux virtual machine on the user’s Mac. It is moving to Anthropic’s servers: scheduled tasks already run there, and from 6 October 2026 new Pro and Max tasks will too, although local files and computer use still need the desktop app. The cloud makes “close your laptop and come back to a finished report” possible, but more user data sits on Anthropic’s infrastructure during the task.
Models and fallback
Fable 5.1 and the 5.5 models include classifiers for cybersecurity and biology requests; flagged requests fall back to another model (Opus 4.8 or Sonnet 5, and for some Fable 5.1 biology tasks, Opus 5). Anthropic says Fable 5.1 causes around 60% fewer interventions per Claude Code session. A community GitHub issue from August 2026 argues the fallback was “effectively silent in practice” and degraded rerouted tasks. That is a user claim, not a confirmed finding, but silent model switching is a UX problem as well as a safety measure.
The Claude agent experience through a product designer’s lens
Interaction model. Conversation is the entry point, but the output is increasingly an object: a document in Claude Docs, a deck, a folder, a pull request. The chat thread becomes a log of work.
Task initiation. Tasks start from a prompt, a schedule, a phone (Dispatch lets users assign work from mobile) or a trigger such as a GitHub Action. The merged app removes the mode switch, which is convenient but moves an important decision from the user to the model.
Delegation. The user hands over folders, connectors, a browser session with existing logins and sometimes the whole screen. Using existing sessions is what makes Claude in Chrome useful on internal dashboards, and also what makes it risky.
Visibility. In Claude Code every tool call and diff is visible. In Chrome the user can watch the cursor. Cloud tasks become a timeline checked later, so the product depends on good summaries.
Control. Cowork documents three approval modes (manual, auto and skip); the merged app asks before acting by default. Claude Code has rollback checkpoints. Desktop computer use adds per-app permission and blocks sensitive apps such as finance and health by default.
Trust. Trust signals are mostly procedural: prompts, site permissions, classifiers. Simon Willison noted in January 2026 that asking ordinary users to “monitor Claude for suspicious actions that may indicate prompt injection” assumes skills most lack.
Feedback. Progress appears as plan steps and tool calls. The April 2026 postmortem shows the fragility: one cause of the regression was a prompt limiting text between tool calls to 25 words.
Errors. Anthropic admits “complex tasks sometimes need a second try, and working through your screen is slower than using a direct integration.” Recovery is mostly retry, rollback or manual correction.
Completion. A finished artifact and a summary signal completion, so the summary’s accuracy carries heavy weight.
Memory. Claude has chat memory, and Claude Code relies on project files such as CLAUDE.md. Features referenced in the March 2026 source leak should be treated as unannounced.
Permissions. This is the strongest and weakest area. Admins get per-tool connector permissions, role-based access, spend limits and OpenTelemetry monitoring. Individuals get dialogs that are easy to approve unread, a pattern our piece on designing AI features people trust examines.
Real-world use cases for an agentic Claude
These reflect documented capabilities; results vary.
1. Codebase migration (developers). Task: upgrade a large service. Agent action: Claude Code reads the repository, edits files, runs tests and iterates. Human involvement: review diffs and approve risky commands. Result: a branch ready for review. Anthropic cites Stripe using Fable 5 on a very large Ruby migration, a vendor-published claim.
2. Pull request upkeep (engineering teams). Task: fix failing CI and answer review comments. Agent action: Claude Code in GitHub Actions reads logs and pushes fixes. Human involvement: final review. Result: shorter cycles on routine changes.
3. Front end verification (developers and designers). Task: check a built page for defects. Agent action: Claude Code builds; Claude in Chrome opens the page and reads console errors and DOM state. Human involvement: judge visual quality. Result: a defect list with evidence.
4. Legal research (professionals). Task: collect relevant case law. Agent action: Claude uses a research database in the browser, finds related cases and files them. Human involvement: judge relevance. Result: an organised research set, a workflow quoted in Anthropic’s September post.
5. Vendor portal reporting (operations). Task: pull monthly figures from a portal with no API. Agent action: Claude in Chrome uses the logged-in session to export data and compile a summary. Human involvement: verify totals. Result: a recurring report without manual clicking.
6. Deck production (marketers and founders). Task: turn research into a presentation. Agent action: Claude builds a deck in Claude Slides (beta). Human involvement: rework narrative and visuals. Result: a first draft, not a final deck.
7. Security review (security teams). Task: find vulnerabilities. Agent action: Claude Code, or Mythos-class models for vetted organisations, identifies issues. Human involvement: triage and patch. Result: Mozilla reported 271 security bugs found with Claude Mythos Preview and fixed in Firefox 150 in April 2026, a vendor-reported figure.
8. Internal agents (businesses). Task: deploy a support or operations agent. Agent action: developers build on the Agent SDK and host on Managed Agents with scoped permissions and tracing. Human involvement: design escalation rules. Result: Anthropic lists Notion, Rakuten, Asana and Sentry as early customers.
What changes for product designers
If an agent can operate any interface, it is tempting to conclude interfaces matter less. Anthropic’s own hierarchy (connectors first, browser second, screen last) suggests otherwise: products without a machine path get operated through screenshots, slowly and with more mistakes. Interface quality becomes a reliability issue.
Dashboards become review surfaces. When an agent compiles the numbers, the dashboard’s job shifts to verification: where a figure came from, what changed, what was skipped. Our SaaS dashboard design principles still apply, with provenance moved up the list.
Forms need stable semantics. Agents rely on labels, field order and validation text. Ambiguous labels and colour-only errors hurt agents and people alike, so good form design practice is now agent readiness.
Navigation needs addressable states. An agent that can deep-link to a filtered view beats one clicking through five menus. Every important state should have a URL.
Autonomous activity needs a visual language. Users need to see which changes the agent made, when and under whose authority, with undo that works on agent actions.
Permissions need plain language. “Allow Claude to act on this site” is not the same as “Claude can pay with your saved card,” which makes UX writing and microcopy a safety discipline.
Conversation complements the graphical interface. The merged app still produces documents and slides people edit directly. Conversation requests the work; the interface checks and finishes it.
What changes for developers
Expose actions, not just pages. MCP is governed by a neutral foundation and, per the MCP project, supported in ChatGPT, Gemini, Copilot, Cursor and VS Code. An MCP server gives any major agent a structured way in.
Design scopes for agents. Separate read from write, and give destructive actions their own scope and confirmation hooks.
Assume prompt injection everywhere. Anthropic’s documentation lists it first among computer-use risks and recommends a minimal-privilege virtual machine and a domain allowlist. In the Cowork exfiltration, a hidden instruction in a document made the agent upload files to an attacker’s account through an allowed API.
Instrument everything. Managed Agents ships with tracing, and Cowork’s April release expanded OpenTelemetry monitoring. The April postmortem showed three separate changes (lower default reasoning effort, a caching bug, a prompt tweak) combining into a quality drop that took seven weeks to resolve. Plan for broad evaluations and staged rollouts.
Budget per task. Computer use adds thousands of tokens per request plus every screenshot, and consumer plans throttle on five-hour and weekly windows.
Protect keys. Anthropic’s September 2026 threat report says stolen API keys are now both a target and a tool for attackers.
Prefer structured outputs. Clean JSON with stable field names chains far better than prose.
Competitive comparison: Claude versus other computer-use AI agents
The table compares documented capabilities as of 30 September 2026, including each product’s constraints. It is not a ranking.
| Dimension | Anthropic Claude | OpenAI dots and Codex | Google Gemini | Perplexity Computer |
|---|---|---|---|---|
| Computer use | API toolset released; desktop computer use in beta for Pro and Max, desktop app must stay open | Each dot works on its own cloud computer; local computer access off by default; Agents API computer use (29 Sep 2026) | Computer use in the Gemini API; Android UI automation in limited beta | Isolated cloud environments; Personal Computer on Mac (Pro and Max from 7 May 2026) and Windows |
| Browser control | Claude in Chrome, GA on paid plans; Chrome desktop only | Through the dot’s cloud computer | Chrome auto browse for US AI Pro and Ultra | Browser in each task environment |
| Background execution | Cloud tasks and schedules in the Claude app; Managed Agents (beta) | Always-on dots with proactive, read-only research in connected apps | Gemini Spark: cloud tasks and schedules, up to 15 concurrent (beta) | Long-running asynchronous tasks |
| Coding | Claude Code, GA since May 2025 | Codex CLI and cloud environments | Jules; Antigravity harness | Orchestrates 20+ models rather than one coding agent |
| Integrations | MCP connectors; plugin directory | Plugin platform, 4,000+ apps per OpenAI | Google apps plus MCP connections | Hundreds of connectors; 400+ apps claimed for Enterprise; custom MCP |
| User control | Manual, auto or skip approval modes; app blocklists | User-set rules; approval before sending | Confirmation before purchases and posts | Model choice per subtask; approval for sensitive local actions |
| Availability | Paid plans; merged app rolling out to Pro and Max first | Pro and Business Premium (rolling out); beta for Enterprise, Edu, Healthcare | Spark beta for AI Pro and Ultra, personal accounts, not in EEA, UK, Switzerland or Nigeria | Pro, Max and Enterprise, credit metered; Max only at launch, 25 Feb 2026 |
Each column has gaps. Claude’s browser agent is limited to one desktop browser and its desktop computer use is still beta. OpenAI’s dots are designed as always-on agents but sit behind premium plans. Google’s Gemini Spark is built into Google’s own mail, documents and browser. Perplexity routes work across many vendors’ models, and its launch post named Claude Opus 4.6 as its core reasoning model, so Anthropic is both a competitor and a supplier in this market.
The business model behind Claude’s agents
Anthropic earns from agents through subscriptions, API tokens and hosted runtime. A chat reply might use a few thousand tokens; a computer-use session can use hundreds of thousands, because each step carries screenshots and history. Caching and cheaper models are therefore central: Opus 5.5 cut cache reads from $0.50 to $0.20 per million tokens, and Fable 5.1 cut them by 75%.
Managed Agents’ $0.08 per session-hour fee is a move from selling intelligence to selling infrastructure, and appears designed to capture companies that would otherwise build their own sandboxes.
On the consumer side, flat subscriptions collide with variable agent costs, hence weekly caps and premium seats. After the April 2026 regression Anthropic reset usage limits for all subscribers, which shows how closely perceived quality and value are linked.
In February 2026 Anthropic reported a $14 billion run-rate and more than 500 customers spending over $1 million a year. A plugins directory opened to developer submissions on 25 September 2026. The restricted Mythos tier, sold only to vetted organisations, is plausibly as much a regulatory posture as a revenue line.
Limitations and risks of Claude’s agentic direction
Prompt injection (demonstrated). In the August 2025 Chrome pilot, browser use without mitigations had a 23.6% attack success rate, falling to 11.2% with them. For the August 2026 GA, Anthropic reports 0% for Opus 5, Sonnet 5 and Mythos 5 and 0.3% for Fable 5 against its test set. These are internal tests, not proof against novel attacks.
Shipped with known flaws (demonstrated). PromptArmor showed Cowork exfiltrating files two days after its January 2026 preview. In October 2025 The Register had reported researcher Johann Rehberger’s demonstration of the same Files API route in Claude; Anthropic first closed his report as out of scope, later said it was closed in error, and pointed users to its existing guidance to monitor Claude.
Quality regressions (demonstrated). The April 2026 postmortem confirmed three causes of degraded Claude Code output between 4 March and 20 April 2026. Opus 4.7 also drew developer complaints about false refusals, reported by The Register in April 2026. Community claims that generation 5 models are more verbose remain unconfirmed.
Misuse (demonstrated). Anthropic disclosed in November 2025 that a group it assessed as Chinese state-sponsored used Claude Code to automate most of an espionage campaign. Its September 2026 report says a majority of the operations it describes involved AI “via direct execution or orchestration.”
Supply chain and operations (demonstrated). On 31 March 2026 a packaging error published Claude Code’s source through npm. Anthropic said no customer data or credentials were exposed. Attackers quickly registered typosquatted packages and fake repositories carrying malware.
Model autonomy (demonstrated in testing). According to Futurism’s reading of the Mythos Preview system card, Anthropic ran a test in which the model was instructed to escape a sandbox and message a researcher, which it did, and then, without being asked, posted details of its exploit on obscure public websites.
Privacy (structural). Moving Cowork tasks to the cloud from 6 October 2026 means more work happens on Anthropic’s servers. Mythos-class models carry a 30-day retention policy for safety purposes.
Lock-in (theoretical but plausible). MCP is open, but skills, plugins, Managed Agents and approval settings are Anthropic-specific. Our note on when not to use AI applies: some workflows are better left deterministic.
Accountability (unresolved). When an agent in a logged-in session buys something or sends a message, the audit trail is thin. No vendor has solved this.
What Claude’s direction reveals about the future of AI agents
From answering to acting: supported. Anthropic’s product line now defaults to action. The merged app decides on its own when a request needs agentic work.
From sessions to continuity: partly supported. Cloud tasks and schedules give continuity; memory remains shallow.
From apps to agents: early evidence. Claude in Chrome targets systems without integrations, suggesting agents will sit on top of existing applications for years.
From interfaces to capabilities: supported for developers. MCP adoption across rival vendors is the strongest evidence that software is being described as actions as well as screens.
From prompts to outcomes: supported, with caveats. “Hand over a report due at noon” is Anthropic’s own framing. The reliability record shows that outcome-based delegation still needs review.
What founders should pay attention to
Vertical agents on horizontal infrastructure. Managed Agents and the Agent SDK lower the cost of building agents for specific industries. The defensible part is domain workflow, data and trust, not the loop itself.
Agent-compatible SaaS. Without an API or MCP server, agents reach your product through the browser, slowly and fragilely, while a competitor with a clean machine interface is preferred by the agent’s hierarchy.
Security and observability. Prompt injection defence, credential isolation, audit trails and agent behaviour monitoring are open problems that Anthropic’s own incidents highlight.
Supplier risk. Anthropic is both platform and competitor. In June 2026 a US export control directive barring foreign nationals from Fable 5 and Mythos 5 forced Anthropic to disable both models for all customers from 12 June until the directive was lifted at the end of the month. Model access can change for reasons outside a startup’s control.
What designers should start doing now
- Map every important action in your product and decide whether an agent should be able to perform it, with what scope.
- Give every meaningful state a URL and every control an accessible name.
- Design permission screens that describe consequences, not capabilities.
- Build activity logs that attribute changes to agents and allow undo per action.
- Treat progress feedback as a first-class surface, including for tasks the user is not watching.
- Make destructive actions reversible or require explicit confirmation that an agent cannot supply on its own.
- Prototype review flows where a human checks agent output quickly, which our guide to AI agents in product design explores further.
Final takeaway: what changed
What changed is that computer use stopped being the headline. In 2024 the novelty was that Claude could move a cursor. In 2026 Anthropic’s own products treat the cursor as the fallback, used only when no connector or browser path exists. What Anthropic now sells is a set of parts: an open protocol, a developer harness, hosted runtime, permission settings and a model family tiered by risk. Customers do delegate real tasks to it, and the record of injections, regressions and contested fallbacks shows that oversight is still required.
Designers should watch how the merged app decides between chatting and acting; developers, MCP governance and the production computer-use toolset; founders, Managed Agents pricing and the plugins directory; users, the approval settings, because the default is where most risk sits.
Building software that people and agents will both use? hello@beconfidency.agency, we design agent ready products with clear actions, honest permissions and interfaces that hold up when a machine is doing the clicking.
This thinking shapes our AI design and integration service.
Sources
- Introducing computer use, a new Claude 3.5 Sonnet, and Claude 3.5 Haiku, Anthropic, 22 October 2024
- Introducing the Model Context Protocol, Anthropic, 25 November 2024
- Introducing Claude 4, Anthropic, 22 May 2025
- Piloting Claude for Chrome, Anthropic, 25 August 2025 (updated December 2025)
- Introducing Claude Sonnet 4.5, Anthropic, 29 September 2025
- Making Claude Code more secure and autonomous with sandboxing, Anthropic, 20 October 2025
- Disrupting the first reported AI-orchestrated cyber espionage campaign, Anthropic, November 2025
- MCP joins the Agentic AI Foundation, Model Context Protocol Blog, 9 December 2025
- Introducing Claude Opus 4.6, Anthropic, 5 February 2026
- Anthropic raises $30 billion Series G funding at $380 billion post-money valuation, Anthropic, 12 February 2026
- Put Claude to work on your computer, Anthropic, 23 March 2026
- Claude Managed Agents: get to production 10x faster, Anthropic, 8 April 2026
- Making Claude Cowork ready for enterprise, Anthropic, 9 April 2026
- An update on recent Claude Code quality reports, Anthropic, 23 April 2026
- Claude Fable 5 and Claude Mythos 5, Anthropic, 9 June 2026
- Statement on the US government directive to suspend access to Fable 5 and Mythos 5, Anthropic, 12 June 2026
- Introducing Claude Opus 5, Anthropic, 24 July 2026
- Claude in Chrome is generally available, Anthropic, 26 August 2026
- Introducing Claude Fable 5.1 and Claude Mythos 5.1, Anthropic, 1 September 2026
- Detecting and countering misuse of AI: September 2026, Anthropic, September 2026
- Claude Cowork and chat are now one Claude, Anthropic, 16 September 2026
- Introducing Claude Opus 5.5, Anthropic, 22 September 2026
- Introducing Claude Sonnet 5.5, Anthropic, 28 September 2026
- Computer use tool, Claude Platform Docs, accessed 30 September 2026
- Get started with Claude Cowork, Claude Help Center, accessed 30 September 2026
- Use Claude Cowork on web, desktop, and mobile, Claude Help Center, accessed 30 September 2026
- Plans and pricing, Anthropic, accessed 30 September 2026
- Anthropic Release Notes, September 2026, Releasebot, September 2026
- DevDay 2026 Recap, OpenAI, 29 September 2026
- Introducing Perplexity Computer, Perplexity, 25 February 2026
- Gemini in Chrome with auto browse comes to Android, Google, 12 May 2026
- The Gemini app becomes more agentic, delivering proactive, 24/7 help, Google, 19 May 2026
- Use Gemini Spark to manage your tasks & workflows in Gemini Apps, Google Gemini Help, accessed 30 September 2026
- Computer for Pro subscribers, Computer for Slack, and Personal Computer, Perplexity, 12 March 2026
- First impressions of Claude Cowork, Anthropic’s general agent, Simon Willison, 12 January 2026
- Claude Cowork Exfiltrates Files, PromptArmor, January 2026
- Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork, The Register, 15 January 2026
- Anthropic Gives Claude Access to Your Desktop, Reworked, March 2026
- Claude code will send your data to crims … if they ask it nicely, The Register, 30 October 2025
- Claude Opus 4.7 has turned into an overzealous query cop, devs complain, The Register, April 2026
- Anthropic disables Fable and Mythos AI models after U.S. government bars it from giving foreigners access, Fortune, 13 June 2026
- Behind the Scenes Hardening Firefox with Claude Mythos Preview, Mozilla Hacks, May 2026
- Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms, The Hacker News, April 2026
- Anthropic Opens Claude Cowork to All Paid Plans on macOS, Windows, eWeek, April 2026
- Anthropic Warns That “Reckless” Claude Mythos Escaped a Sandbox Environment During Testing, Futurism, April 2026
- Anthropic is killing off Claude Cowork and folding it into Claude chat, VentureBeat, 16 September 2026
- Measurable quality regression in Claude generation 5 (issue #83510), GitHub community report, August 2026
- Claude (language model), Wikipedia, accessed 30 September 2026
