What Changed in AI This Week? Claude Cowork in Chrome, ChatGPT Business Pricing, UK Ads and Cyber AI
What Changed in AI This Week? Claude Cowork in Chrome, ChatGPT Business Pricing, UK Ads and Cyber AI
Claude moved deeper into the browser, OpenAI introduced new Business pricing and UK ads, and specialist cyber AI became available through AWS.
AI moved further out of the chat box this week and into browsers, budgets, audit trails and security operations. For businesses, the practical priorities are clearer controls around browser agents, proper evidence trails, licensing based on real usage and stronger separation between approved AI services and unmanaged personal accounts.
In the tail end of the UK’s fifth heatwave, it’s something of a relief to write an update that doesn’t turn up the heat on AI any more. AI hasn’t ‘gone rogue and escaped its testing area’ (at least for this week, anyway).
Instead, this week, it’s moved further out of the chat box and into browsers, budgets, audit trails and security operations, so without further ado, let’s jump into it, shall we?
Headlines at a glance
Claude in Chrome becomes Claude Cowork
Browser sessions now span Claude's desktop, web and mobile apps, with skills and connectors available in the side panel.
Anthropic closes part of the audit gap
Its Compliance API now covers Cowork and Claude Code sessions in beta for Enterprise customers.
ChatGPT Business gets a premium seat
OpenAI is introducing a higher-capacity option at $125 per user per month, or $100 on an annual plan, while allowing mixed seat types in a single workspace.
ChatGPT ads arrive in the UK
The pilot is now live for eligible Free and Go users, while paid individual and business tiers remain ad-free.
OpenAI puts specialist cyber models into AWS
Approved security teams can access Daybreak Blue and Red through Amazon Bedrock, including the new GPT-5.6-Cyber model for advanced defensive work.
There’s a fairly clear theme running through all of this week’s updates, in that AI vendors are no longer selling only a ‘clever answer’ to a prompt. They’re selling systems that can act across tools, consume more resources, create records for auditors and, increasingly, open new commercial channels. Useful, certainly.
Claude Cowork in Chrome: the browser becomes part of the workflow
Now, it’s important to start by saying that the extension itself is not new, as Anthropic first piloted it in August 2025, but now Claude is available in a Chrome side panel, which runs as a Claude Cowork session.
Could you argue that it’s just a lot of words to say it’s a product name change? Not so much, and that’s because conversations are saved to a user's history, skills and connectors work in the browser, and a task started in Chrome can be continued in Claude on desktop, web or mobile. Anthropic's example is pulling invoice details from several supplier portals into a budget spreadsheet, then continuing the work in the desktop app with local files.
The new side panel is available now on Max and Team plans, and is expected to be rolling out to Pro users over the coming weeks. Enterprise organisations can use it too, but Claude in Chrome is off by default, and administrators can restrict access to approved domains. It remains a Chrome-only experience rather than support for every Chromium (or mobile) browser.
It seems that the browser is becoming an execution layer for AI, as internal dashboards, older line-of-business systems and supplier portals rarely have neat AI connectors. A browser agent can still work with them because it sees and uses the same interface as a person, and it could make automation available in places where a formal integration would have been too expensive or too slow to justify.
Yet, it also increases the consequences of getting the instruction, permissions or security model wrong. Anthropic explicitly warns that prompt injection remains a risk: malicious content on a page, in an email or in a document can try to redirect the agent. A separate check now reviews consequential actions in the automatically approve mode, and Claude still asks before some irreversible or costly actions, but Anthropic is clear that the risk is reduced rather than eliminated.
Treat browser agents as automation with credentials, rather than as a convenient browser add-on. Start with trusted, low-risk sites; use domain allowlists; keep financial, legal and other sensitive workflows out of early pilots; and decide which actions must always require a person to approve them.
Anthropic extends compliance logging to Cowork and Claude Code
A day earlier, Anthropic also announced that its Compliance API now covers Claude Cowork and Claude Code in beta for Claude Enterprise customers.
Security and compliance teams can retrieve session content and metadata through the same interface already used for Claude chats, with the returned records bringing together prompts, responses, web and MCP tool calls, skills, artefacts, verified user details and timestamps. Basically speaking, it means that activity in an agentic session is less likely to disappear into a separate logging blind spot.
There are limits, of course. For example, the beta doesn’t cover Claude Code on the web, sessions accessed through the Claude Platform, or sessions running through Amazon Bedrock, Google Cloud Vertex AI or Microsoft Foundry. Even so, it’s a meaningful sign that governance tooling is starting to follow AI into the places where it actually performs work.
If Claude is moving beyond ordinary chat in your organisation, check whether your audit, eDiscovery and incident-response processes can see those sessions. Approving an agent without approving the evidence trail is an avoidable gap.
ChatGPT Business premium seats: more capacity, at a much higher price
OpenAI has announced Premium seats for ChatGPT Business, aimed at the people who use the service most heavily.
Premium provides five times the usage of a Standard seat, removes the five-hour usage limit and uses predictable weekly resets. It costs $125 per user per month, or $100 per user per month on an annual billing plan. Standard remains $25 monthly or $20 with annual billing. OpenAI says both seat types can sit in the same Business workspace, with administrators able to upgrade, reassign and monitor usage centrally.
That mixed-seat model is what’s particularly of note here, as AI use in any business case is rarely uniform. A developer running longer Codex tasks, an analyst working across large data sets and an occasional user drafting emails don’t all need the same allowance, so buying the highest tier for everybody would be handy, for sure, but expensive. Splitting people into the right capacity band is more sensible, provided someone reviews whether those premium seats deliver premium value.
The offer isn’t generally available everywhere yet, and OpenAI is asking workspace owners to join a waitlist, with some eligible customers receiving early access. A limited promotion offers workspace credits for early sign-ups and ends on the 20th of August, so if you want in, you should act fast. Businesses should also remember that the published prices are in US dollars; so, a few factors need to be checked and considered before building a UK budget around them.
Don’t turn premium AI access into a status perk. Assign it to defined workflows, record the expected time or output gain, review real usage after a month, and move the seat if the value is not there.
ChatGPT ads launch in the UK
On the 11th of August, OpenAI updated its ChatGPT advertising pilot to confirm that ads have launched in the UK, Mexico, Brazil, Japan and South Korea.
Currently, the test applies to logged-in adult users on the Free and Go tiers, while Plus, Pro, Business, Enterprise and Education accounts remain ad-free. OpenAI says sponsored placements are labelled and visually separated from the answer, don’t influence ChatGPT's responses, and aren’t eligible to appear around sensitive or regulated topics such as health, mental health or politics. Equally, advertisers receive aggregate performance information rather than access to a user's chats or personal details.
People increasingly use AI systems when comparing options or working towards a decision, which makes conversational advertising potentially valuable, but buying models, formats, and measurement standards are still developing. OpenAI itself describes the programme as a test, so any businesses thinking they need to rush out and advertise there should treat it accordingly.
There is also an internal policy point to keep in mind. Staff using a free personal ChatGPT account may now see advertising alongside work-related research, whereas approved Business and Enterprise workspaces are ad-free and provide organisational controls. If nothing else, that should be another small reason to give employees a sanctioned route, rather than leaving business AI use to personal accounts.
Marketing teams should monitor the pilot and register interest if the audience fit is strong, but avoid treating it as a mature channel just yet. IT leaders should use the change as another prompt to separate approved business use from unmanaged personal accounts.
OpenAI Daybreak brings advanced cyber AI to AWS
OpenAI has expanded its Daybreak security programme with two controlled access tiers and a specialist model, GPT-5.6-Cyber. A day later, it confirmed that Daybreak Blue and Daybreak Red are available through Amazon Bedrock for approved customers.
Daybreak Blue provides frontier general-purpose models with safeguards tailored to authorised defensive work. Daybreak Red is intended for advanced vulnerability research, exploit validation and security testing, and includes GPT-5.6-Cyber. Access isn’t a normal self-service model choice: OpenAI requires enrolment and says it uses identity checks, account security, monitoring, approved-use restrictions and legal attestations.
The technical capabilities are significant. In its Daybreak announcement, OpenAI says the model helped identify previously unknown vulnerabilities in Chrome's V8 engine, which were reported to Google and fixed. It also says the model is designed to refuse fewer legitimate, high-risk defensive requests than a general-purpose model. Just bear in mind that these are OpenAI's own evaluations and examples, so they should be read as vendor evidence rather than an independent benchmark.
For most SMEs, Daybreak Red won’t be something to procure next week, but it does indicate changes to the threat environment. Advanced vulnerability work is being compressed and automated, and defensive teams may benefit, but attackers will be looking for similar leverage. Patching, identity protection, logging and incident response therefore, become more important as AI security tools improve.
Ask your security provider how AI-assisted vulnerability discovery and incident response fit into its service, but keep the basics measurable: patch speed, multifactor authentication, privileged access, tested backups, monitoring and a rehearsed response plan.
The wider pattern: access is no longer the same as adoption
OpenAI also published two enterprise studies this week, noting that the top 10% of enterprise customers by monthly AI usage now generate 8.3 times as many output tokens per active user as a typical firm, up from 2.6 times in January. It also reports rapid growth in enterprise Codex use outside engineering, including legal, sales, recruitment and marketing. The full enterprise adoption summary is worth reading, with the usual caveat that the analysis comes from the vendor's own customer base and usage measures.
Still, the practical conclusion is pretty sound, and reads as this: giving everyone a licence doesn’t create a useful operating model. The organisations getting further on their journey appear to be connecting AI to context and tools, turning good individual workflows into repeatable team practices, and putting permissions, review and governance around them.
You may have noticed that this week's other announcements fit that pattern too. Claude can now continue work across the browser and its other apps. Compliance records follow those sessions. OpenAI is creating different capacity bands for different users. Ads are turning AI into a commercial channel. Cyber models are moving into governed cloud environments. The products are becoming less separate from ordinary work, which means ownership matters more.
Quick answer: what should SMEs do about AI this week?
Review any browser-agent pilots
Confirm which sites, accounts and actions are allowed, and where human approval is mandatory.
Check the evidence trail
Make sure AI activity in coding, browser and multi-step agent sessions is visible to the people responsible for security and compliance.
Segment AI licensing by real need
Heavy users may justify premium capacity; most users will not. Measure before expanding.
Separate business AI from personal accounts
Approved workspaces give you clearer controls and, in ChatGPT's case, avoid the new advertising experience.
Ask whether your cyber programme is keeping pace with AI-assisted attack and defence, then verify the fundamentals rather than buying into a dramatic product claim.
Fifosys view
The most important AI development this week is the steady shift of AI from a tool people visit into a layer that sits inside browsers, workspaces, security operations, and commercial journeys.
Long term, that should make AI more useful, but it also makes vague ownership harder to defend. Once an agent can use a logged-in browser, carry context across devices, call business tools and leave records for auditors, the question is no longer simply whether staff are allowed to experiment. The questions are who can delegate what, using which data, under whose budget, with what evidence and what happens when it goes wrong.
None of that requires a 40-page AI strategy in place and rolled out to all staff via email before Friday’s out. But it does require a few named owners, a small number of approved workflows, and enough monitoring to tell whether the technology is saving time or merely shifting cost and risk to a less visible place.
Claude Cowork in Chrome is probably the most useful example of this, as the feature could remove a lot of tedious copying between systems. But the right response to it, if your business is on an Anthropic-backed AI journey, isn’t to take a blanket approach of ‘let’s just switch it on everywhere!’. Instead, pilot it where the value is clear, the sites are trusted, and the consequences of a mistake are manageable. That may be less exciting than announcing an AI transformation, but it’s also much more likely to work.
This week's AI news FAQs
What changed with Claude in Chrome?
What are ChatGPT Business Premium seats?
Are ChatGPT ads now live in the UK?
What is GPT-5.6-Cyber?
What should SMEs prioritise this week?
Ready to make business AI useful, secure and manageable?
We can help you identify valuable use cases, run controlled trials and put the right governance around the tools your people use.
Talk to our team
Discuss your AI priorities, current adoption and the risks or uncertainty holding progress back.
AI for business
See how Fifosys helps organisations adopt AI around real workflows, clear controls and measurable value.