Claude in Chrome Went GA on Wednesday. Every Account Manager at Your Agency Now Has an Agent That Uses Their Seller Central Login.
📢
← Back to Blog

Claude in Chrome Went GA on Wednesday. Every Account Manager at Your Agency Now Has an Agent That Uses Their Seller Central Login.

John Aspinall · · 7 min read

The most important sentence in Wednesday's announcement is not about capability. It is nine words in the feature list: Claude can act in the browser "using your existing logins."

On Wednesday, August 26, Anthropic made Claude in Chrome generally available on every paid Claude plan, and it now takes actions autonomously rather than asking for approval each step, with a safety classifier checking each action against the request. The same day, Claude Cowork got a built-in browser in the desktop app, sandboxed with no stored logins by default, with an option to import credentials from Chrome, Edge or Firefox. Banking, email and SSO sites are excluded from that import unless you enable them.

Seller Central is not on the exclusion list. Neither is the ads console. Neither is Brand Registry.

Here is what changed for a brand paying an agency to run its Amazon account: the person managing your catalog on a $20-a-month Pro seat can now hand a browser agent their logged-in session and say "fix the bullets on these forty ASINs." It will do it. It will do it faster than they would have. And nothing about the arrangement between you and the agency, the plan they're on, or Amazon's own rules changed to accommodate it.

Why most brand owners will read this wrong

The dumb take is "AI agents are going to run Seller Central now." They are not. A browser agent operating a listing form is slow, expensive per task, and bad at exactly the thing marketplace work demands, which is knowing the difference between a field that didn't load and a field that was empty. I've written the build log for a read-only version of this on my own machine and the interesting failures were always the confident ones.

The second dumb take is "we're not on Claude, so this doesn't apply." OpenAI's agent runs in a browser. Perplexity's agent is the one a court just said is the user's access, not the vendor's. Anthropic shipping GA on every paid seat is the moment this stopped being a beta feature a few engineers had and became something a 24-year-old account manager can switch on before lunch. That's the signal. Not the model. The seat.

What actually changes for a $200K/mo brand

The access surface moved from the person to the person plus a tool. I've spent a month telling operators to run an access audit before peak: who holds what on Seller Central, the ads console and Brand Registry, and whether the business or an individual owns the primary login. That audit had a hidden assumption in it. It assumed that a login was used by the human it was issued to. As of Wednesday, a login is used by the human and by whatever they've pointed at the page. Your permission structure didn't get weaker. It got a second occupant.

The audit log I told you to ask for lives on the wrong plan. Last week I wrote that Anthropic's Compliance API can return a per-session transcript with a verified user ID and that the RFP question had finally become "can you produce the session record." That's still true and it's still Enterprise-only. The Chrome extension went GA on Pro. On Pro, there is no admin, no domain allowlist, no session record. Enterprise admins can limit the extension to approved domains in Organization Settings. The agency AM on a personal Max plan has none of that. So the plan the agency's staff are on now decides whether the work done on your account is auditable, and I'd bet most agencies could not tell you which plan each employee is on if you asked.

Amazon's paperwork already points at you, not the agent. Section 19 of the Business Solutions Agreement, effective March 4, covers Agents accessing Amazon Services and requires them to identify themselves as automated. That obligation sits on the seller account. A browser agent operating a logged-in session under an agency employee's user is, as far as your account health is concerned, your automation. Nobody is enforcing that against a Chrome extension today. I'd rather you know where the obligation sits than find out in a policy warning.

The Sept 3 role reset is landing in the same week. Amazon is rebuilding provider authorization in Seller Central right now. Providers verify role coverage by September 3 and the seller-side reauthorization wave follows. That's the only moment in years you get to rebuild what an outside party can touch from zero. Doing it the same week their staff got autonomous browser agents on subscription seats is either good timing or bad, and it's your choice which.

Margin: nothing. I hold the position I've held since July. Attributable AI cost inside a $6K retainer is low hundreds. A browser agent doing bulk listing edits does not reduce the cost of the person who checks the edits, and that person is the retainer. If an agency tells you this lets them lower your fee, ask what they were paying the AM to do before Wednesday.

What I'd do this week

  1. Add one line to the vendor question set. You already ask which model they pin and whether they can produce a session record. The new line is: does any member of your staff use a browser agent on our Seller Central, ads console or Registry, and on what plan? A shop that answers with a plan name and a list has thought about it. A paragraph about responsible AI is also an answer.

  2. Write the browser-agent rule into the authorization you're about to redo anyway. The Sept 3 reset forces you to re-grant provider roles. Put a sentence in the agreement: no autonomous browser automation on write-capable roles without a named human, a plan with domain controls, and a session record you can request. It costs nothing and it's the first time the paperwork will have said anything on the subject.

  3. Check the import on your own machine. If you or your ops lead use Cowork, open the built-in browser's credential import and see what it offers to pull from Chrome. Seller Central is in there if you've saved it. Deciding not to import it is a decision. Not looking is also a decision.

  4. Treat read-only as the only pre-peak posture. Research, review mining, competitor grids, autocomplete: fine, useful, low downside. Anything that submits a form on a listing, a bid, a price or a case goes through a human until January. Ten weeks from peak is not the moment to find out how a classifier handles a flat-file upload page.

  5. Ask Amazon's rule, not the vendor's. Whatever the extension is allowed to do by Anthropic, the question for your account is what Section 19 says an agent must do. Diary a re-check for early October on whether Amazon has said anything specific about browser agents. Nothing so far. That will change.

What I'd ignore

The 0% attack-success figure. Anthropic reports zero successful prompt injections against Sonnet 5 and Opus 5 with full safeguards on. That is a vendor's number about the vendor's product, measured on the vendor's attack library. Anthropic's own Cowork post says the measures "meaningfully reduce the risk but can't eliminate it." Take the second sentence.

"Agents replace account managers" and its mirror image. Both are content. What shipped Wednesday is a faster pair of hands on a login you already granted. The job of deciding what those hands should touch didn't move.

Any pitch with "agentic account management" on the invoice. That's an AM with a Chrome extension. Make them describe the deliverable in one sentence and ask which plan the extension is on.

The urge to ban it. You can't. It's on their machine, on their seat, in their browser. What you can do is decide which roles it's allowed to hold on your account, and you're about to be handed the form to do it.

For a year the question about agency AI was "which model." Then it was "which record." As of Wednesday it's "which seat," because the seat decides whether there's a record at all. Ask.

Install this as an agent, not a checklist.

The Operator Intelligence: Multi-Agent OS cohort is a 4-week live build: 2-3 specialist agents with their own seats, running real workflows on your actual catalog. Starts Mon, Sep 14 · $499 · 12 seats · replays included.

See the cohort →

Want to see it working first? Watch the free replay — the whole system built live on a real ecommerce business.