Anthropic is expanding Claude Cowork, its AI agent designed for non-developer employees, to web and mobile platforms, enabling enterprise users to delegate tasks to AI agents that can interact with business applications, files and internal systems.
The expansion marks a broader shift in enterprise AI adoption, as autonomous AI agents move beyond developer-focused environments and become accessible to employees across departments. Cowork allows users to connect Claude to tools such as Slack, Gmail, HubSpot and local or shared file systems, and instruct the agent to complete multi-step tasks on their behalf.
Unlike conventional enterprise AI chat tools that primarily provide information or generate content in response to prompts, Cowork is designed to take actions. It can read and write files, search emails, update CRM records, post messages to Slack and retrieve information from connected business systems.
With Cowork now available through the web and mobile, sessions can run in Anthropic's cloud and follow employees across devices. Users can initiate a task on one device and continue working with the agent on another, while scheduled tasks can continue running in the background even when the user's device is offline.
The growing use of autonomous agents also introduces new challenges for enterprise security and governance teams.
An AI agent may execute a chain of tool calls during a single task, potentially accessing files, email accounts, business applications and external services. While individual actions may appear routine, the combination of multiple actions could result in sensitive information being moved or shared in ways that organisations did not anticipate.
Employee-led connections to data sources and business applications can further complicate governance. Employees may connect Cowork to shared drives, email accounts or other systems without going through a formal security review, creating uncertainty around which data sources are accessible to AI agents and how that data is being used.
Overshared folders and overly permissive connectors can also create additional exposure when an AI agent is authorised to access them. The same connector could be appropriate for one business workflow but present compliance risks when used with sensitive or regulated information in another context.
The expansion to web and mobile adds another dimension, as cloud-hosted sessions can continue operating even when employees are not actively monitoring them or when their managed work devices are offline.
To address these challenges, Opsin has announced support for Claude Cowork within its AI governance platform.
The platform will provide security and governance teams with visibility and controls across Claude Cowork, alongside Claude Enterprise and Claude Managed Agents, as well as other enterprise AI platforms including Microsoft Copilot, ChatGPT Enterprise and Google Gemini.
The development reflects a broader challenge facing organisations as agentic AI becomes more deeply integrated into enterprise workflows. Traditional data loss prevention (DLP) and cloud access security broker (CASB) tools are designed primarily around predictable data flows between applications. AI agents, by contrast, can dynamically chain multiple tool calls and move information between email, files, SaaS applications and other systems within a single session.
As a result, organisations will increasingly need to monitor not only what data employees access, but also what AI agents are permitted to do with that data and which systems they can interact with.
The expansion of Claude Cowork illustrates the growing transition from AI assistants that answer questions to autonomous agents that can execute tasks across enterprise systems. As adoption increases, enterprises will need to balance the productivity benefits of agentic AI with stronger controls around permissions, data access, security, compliance and accountability.

