CyberSecurityNews

Claude AI Now Controls Your macOS and Windows Computer in the Background


Anthropic has quietly pushed one of its most consequential agentic upgrades yet, letting Claude take control of a user’s desktop and complete tasks while they work on something else entirely.

The company confirmed this week that computer use inside Claude Cowork and Claude Code can now run in the background, meaning the AI clicks, types, and opens applications the way a human would, without commandeering the screen the user is actively viewing.

The update lands inside the Claude Desktop app for both macOS and Windows, though the background execution mode is currently limited to Mac systems running macOS 15 or later.

On those machines, Claude opens and operates apps in background windows, allowing people to keep typing, browsing, or working in the foreground while the assistant handles a separate task behind the scenes.

Claude AI Controls macOS and Windows

Anthropic says Claude does not seize the mouse pointer or keyboard and will generally pause if a user is mid-keystroke, only requesting full-screen access the first time a session genuinely needs it.

Computer use itself is not brand new. Anthropic introduced the underlying capability for developers through its API in late 2023, and later extended it to everyday Cowork and Claude Code users on Pro and Max subscriptions.

What changes now is the workflow priority and the ability to multitask alongside the model. Inside Cowork, Claude is designed to reach for the fastest and most reliable option first: native connectors such as Gmail, Google Drive, Microsoft 365, or Slack take priority, followed by the built-in or Chrome browser, and only then does the model fall back to direct screen interaction when no connector or browser path exists.

That fallback is where the risk conversation begins. Because screen-level interaction has no sandbox separating the model from whatever is open on the desktop, Anthropic’s own safety documentation warns that computer use carries materially higher exposure than sandboxed code execution or permissioned file access.

Practical use cases the company highlights include compiling competitive research from local files, testing a mobile app inside a phone simulator to spot UX bugs, and navigating internal dashboards or specialized enterprise tools that lack a formal API integration.

For security teams, the feature deserves closer scrutiny than a routine product update. An AI agent with standing permission to click through email clients, internal portals, and developer tools introduces a fresh class of prompt-injection and social-engineering surface, particularly if malicious content on a webpage or file is crafted to hijack the agent’s next action.

Enabling the toggle is done manually through Settings> General> Desktop app, and it remains off by default for anyone who has not previously used the computer.

Enterprises evaluating Cowork should treat background computer use the same way they would a new privileged automation account: reviewed, monitored, and scoped before deployment.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.





Source link