Free Agentic AI Security Workshop Map your footprint, identify your highest-risk gaps, and leave with a customized security summary. Book a Workshop→
Start assessment

This ever-changing world in which we live in: Latest Claude updates add security complexity

September 17, 2026 · Jason Garbis

Claude just became a document repository, and your taxonomy boundaries got blurrier

While Paul McCartney may not be an AI expert, his famously ungrammatical (and oft-misquoted) lyric does accurately capture the feeling of the Agentic AI landscape. Yesterday, Anthropic announced that they’re merging the capabilities and user experience of Claude’s Chat and Cowork capabilities, so there’s no longer a distinction between them. In their words, this “removes the distinction between the two products: in the new experience, these are merged into a single conversation, so you don’t need to decide which option better suits your task before getting started.”

This is legitimately good for end users. Deciding which product a task belongs in was real friction, and removing it makes Claude simpler to use.

It also blurs a line our taxonomy draws deliberately. In Part 7 we made the case that this taxonomy classifies the mode an agent is operating in rather than the product it ships inside, because a single desktop application can behave like a chat assistant one moment and a local-access agent the next. This announcement takes that principle and stress-tests it. A single conversation can now move between asking a question, running work in a sandbox, and reaching into local files, with no visible boundary between them and no signal to your endpoint tooling about which one is active.

There’s a related detail worth noting. Anthropic writes that by default Claude asks before taking an action, and that users can turn on a mode where it keeps working and checks in only when something needs a closer look. That’s a per-user autonomy setting, and as we argued in Part 7, a toggle most people treat as a speed control is doing security work.

The bigger story: Claude is now a document repository

The merge got the headline, but the more consequential change is what Anthropic shipped alongside it. Claude Docs and Claude Slides are new, and Claude Design now works inside conversations.

These are no longer just files generated at the end of a chat. As the VentureBeat article describes them, they’re working documents inside Claude, where outputs live at a single shareable link and remain editable, including from a phone. You can download them as PowerPoint or PDF, but the canonical, editable copy lives at a Claude-hosted URL.

That raises immediate questions:

  • How is access to these artifacts controlled, and who can reach a shared link?
  • Can we apply data classification to them?
  • How do we back them up for compliance or disaster recovery?
  • How do we meet compliance reporting requirements for content that lives here?

I don’t believe there are clear answers yet.

Credit where it’s due, and where the real exposure sits

To be fair to Anthropic, they’ve handled the enterprise side better than most vendors do. Docs, Slides, and Design are in beta, Enterprise admins choose when to turn them on, and Anthropic commits to giving Enterprise admins at least 30 days notice before anything changes for their organizations. That’s a  reasonable rollout process.

But look at where it starts. This is rolling out to Pro and Max first, with Team and Free to follow. Those are personal subscriptions.

So the first place this capability lands is an employee’s personal Claude account, quite possibly on a corporate laptop, creating working documents that live at a shareable link entirely outside your boundary. No admin toggle applies, because there’s no admin. The enterprise controls are real, and they govern the path you were already watching.

What to do this week

Three things, and none of them require waiting for answers.

Find out whether Docs and Slides are enabled in your tenant, and decide deliberately rather than letting the 30-day notice make the decision for you.

Ask how many of your people are using personal Pro or Max accounts on corporate devices. That number is the real scope of this change for most organizations, and most security teams don’t know it.

Treat this as the visibility and governance question it is, not an AI question. If Claude and platforms like it are becoming a living document repository and work environment for your users, they need at least the same level of visibility and control you apply to M365 and Google Workspace. That’s not an unreasonable bar. It’s the one you already set.

References

Discover more from Numberline Security

Subscribe now to keep reading and get access to the full archive.

Continue reading