Claude AI can now control your computer to complete tasks, but security risks remain

Reviewed byNidhi Govil

33 Sources

Share

Anthropic has enabled Claude Code and Claude Cowork to take direct AI computer control of MacOS desktops, allowing the tools to point, click, and navigate screens to complete tasks. Available as a research preview for Claude Pro and Max subscribers, the feature lets AI agents to complete tasks by opening files, using browsers, and running dev tools—though Anthropic warns it's error-prone and raises security concerns.

Anthropic Enables Direct Desktop Control for Claude AI

Anthropic has launched a significant update allowing Claude AI to take direct control of users' computers, joining a rapidly expanding field of agentic AI tools that can autonomously perform tasks on local desktops

1

. The company announced that Claude Code and its user-oriented counterpart Claude Cowork can now "point, click, and navigate what's on your screen" to "open files, use the browser, and run dev tools automatically" when necessary to complete assigned tasks

1

.

Source: PYMNTS

Source: PYMNTS

When possible, Anthropic says these tools will prioritize using Connectors to directly access and control outside apps like Google Calendar or Slack

2

. When that connection isn't available, the Claude computer use feature enables the AI to "scroll, click to open, and explore as needed" on the machine itself, always asking for explicit permission first

5

. This capability to control user's desktop can also be initiated and managed remotely via the Dispatch tool, provided the target computer remains powered on

1

.

Limited Availability and Performance Constraints

The new feature is currently available only to Claude Pro and Max subscribers using MacOS in what Anthropic calls a research preview

1

. This designation signals that the system "won't always work perfectly" and will sometimes require a "second try" for complex tasks, Anthropic warns

1

. Free users and those with Team or Enterprise plans currently cannot access this capability, though the company has indicated Windows support is coming soon

3

.

Completing tasks via AI computer control "takes much longer and is more error-prone" than performing the same task via Connectors, the company acknowledges

1

. Real-world testing revealed that while the AI performed tasks accurately, the process can be slow even with simple operations

3

. Additionally, permissions granted to Claude to access specific applications are only valid for that session, requiring users to grant permission again for different requests

3

.

Security Risks and Safeguards Implementation

Giving an admittedly imperfect and "error-prone" AI tool the ability to explore computer desktops "as needed" raises justified security risks for many users

1

. Experts have noted that one major concern with agentic AI is its ability to take major, sometimes dramatic actions quickly and with little warning, and that these systems can be hijacked by malicious actors who can exploit personal data and systems

2

.

To address these concerns, Anthropic has implemented safeguards to prevent common risks like prompt injection attacks, and will limit access to certain "off limits" apps including investment and trading platforms and cryptocurrency applications by default

1

. The model is trained to avoid "risky operations" such as moving or investing money, modifying files, scraping facial images, or inputting sensitive data

1

.

However, Anthropic openly warns that such training safeguards "aren't perfect" and "aren't absolute," meaning that "Claude may occasionally act outside these boundaries"

1

. When computer use is activated, Claude will be able to see anything visible on-screen, including "personal data, sensitive documents, or private information"

1

. For these reasons, the company recommends "starting with the apps you trust and not working with sensitive data" during this research preview stage

1

.

Safer Auto Mode and Remote Task Management

Anthropic has also launched a safer auto mode for Claude Code, designed to offer users an alternative between constant supervision or granting the model dangerous levels of autonomy

4

. This feature flags and blocks potentially risky actions before they execute, offering the agent a chance to try again or ask users to intervene

4

. Currently, auto mode is only available as a research preview for Team plan users, with access expanding to Enterprise and API users in the coming days

4

.

The Dispatch tool adds another layer of functionality, allowing subscribers to control their computers remotely from their phones to assign tasks to Claude

2

. Tasks can include checking email every morning, opening Claude Cowork or Claude Code sessions, creating morning briefings, or running tests

2

. Dispatch maintains a single thread for all conversations and remembers tasks to better understand workflow, though users can view, edit, and delete their memory at any time

5

.

Source: 9to5Google

Source: 9to5Google

Competing in the Emerging AI Agent Landscape

Anthropic's announcement arrives just weeks after the rollout of similar capabilities from competitors including Perplexity's Personal Computer, Manus's My Computer, and Nvidia's NemoClaw

1

. These corporate moves follow the viral spread of OpenClaw earlier in the year, which led OpenAI to hire OpenClaw creator Peter SteinBerger "to drive the next generation of personal agents"

1

. This rapid development suggests the AI industry views desktop control as a critical capability for next-generation AI agents that can interact with applications and files to deliver more sophisticated automation.

Source: 9to5Mac

Source: 9to5Mac

As this technology matures, users should watch for improvements in execution speed, accuracy rates, and more granular permissions controls that allow permanent app access where appropriate. The balance between convenience and security will likely define which platforms succeed in this space, particularly as businesses evaluate whether to deploy these tools across their organizations with sensitive data at stake.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo