Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Let Claude Do the Work, Not Just Answer
claudecowork-me.com
LATEST
After Your Account Moves to the New Claude Experience, Where Did Cowork's Global Instructions and Storage Folder Go?  ·  Five Things You Still Can't Do After Cowork Merges Into Chat — Especially the Incognito One  ·  Claude Cowork Is No Longer a Separate Tab: Anthropic Merges It Into Chat, Launches Docs and Slides  ·  Cowork Can Now Operate Your Computer in the Background — But Anthropic Itself Says the Guardrails "Aren't Absolute"  ·  A Note for Healthcare Teams: Claude Cowork Isn't Covered Under Anthropic's HIPAA BAA, No Matter Your Plan Tier  ·  What Does the Effort Control in Cowork Actually Adjust? It's Not the Same Thing as Switching Models
news

Cowork Can Now Operate Your Computer in the Background — But Anthropic Itself Says the Guardrails "Aren't Absolute"

30-Second Version · For the impatient
Straight from Anthropic: these guardrails are trained in, but they aren't absolute — don't rely on them as a substitute for blocking access to sensitive apps.

Full Explanation +
01 · Why did this happen?

Can Team or Enterprise plan users get early access to this feature somehow?

There's currently no official path to unlock it early. Anthropic's documentation explicitly limits this feature to Pro and Max plans — Team and Enterprise plans have no access at all right now. This isn't a hidden setting waiting to be manually turned on; it's a plan-tier limitation, unrelated to account configuration or usage habits.

If your organization is on a Team or Enterprise plan, the more practical approach is watching for future official announcements about whether this expands to those plans, rather than trying to unlock it early through any unofficial route — especially given that this particular feature involves direct control over your computer screen, enabling an untested feature that hasn't been officially tuned for that plan tier through unofficial means carries higher risk than it would for an ordinary feature.

02 · What is the mechanism?

In background mode, if Claude is operating one app while I open another window to do my own work, could that cause interference or operation errors between us?

Anthropic's design accounts for this scenario — Claude works in a background window and, in principle, doesn't take over whatever window you're currently using, so you can keep working in your own window. Worth noting, though: the documentation's phrasing that it "generally waits" if you're mid-typing uses "generally," not "always," meaning this avoidance mechanism isn't a 100% guarantee against any timing overlap — it just avoids the moment you're actively typing in most cases.

If the work you're doing genuinely requires precise timing or uninterrupted operation (a sequence of continuous keystrokes that can't be broken, say), the more conservative approach is not running Claude in the background during that specific window when you genuinely need uninterrupted focus, rather than fully trusting that the "generally waits" mechanism applies to every situation.

03 · How does it affect me?

Anthropic recommends not granting access to banking, healthcare, or government apps. If I use an app not explicitly named in those categories but that still contains sensitive information (an internal HR system, say), does this recommendation still apply?

Yes, and Anthropic's own wording uses an open-ended phrase like "including but not limited to," meaning banking, healthcare, and government are examples of high-risk categories, not an exhaustive list. The more accurate standard for judging whether an app should be excluded from computer use authorization isn't "was it explicitly named by Anthropic" — it's "how severe would the consequences be if this app's content got mishandled or misread." An internal HR system might contain employee salaries, personal information, and performance review records — information no less sensitive than what's found in the categories Anthropic explicitly named.

The more solid approach in practice is treating Anthropic's three named categories as a floor of what must be excluded at minimum, not the only scope that needs excluding — and separately taking stock of which other apps on your computer sit at a comparable sensitivity level. Anything meeting the test of "content leaking or being mishandled would cause real damage" is worth proactively excluding from authorization scope, held to the same standard as banking, healthcare, and government apps.

04 · What should I do?

If I follow Anthropic's advice and start with simple tasks, how do I judge when it's safe to hand over more complex, multi-step work?

Anthropic's documentation doesn't give a clear time threshold or number of successful runs, meaning this judgment is inherently subjective and needs to be calibrated by you based on what you actually observe. A more practical basis for the judgment is whether Claude's performance on simple tasks consistently matches your expectations — did it take any action beyond the scope of what you instructed, did it stop to ask in places you didn't expect, how large was the gap between the result and what you wanted. The patterns you observe during these simple tasks help build an understanding of its actual capability boundaries, rather than just checking whether it "succeeded."

Even if performance on simple tasks has been consistently solid, Anthropic's advice to "make sure your prompts are specific and carefully tailored" only becomes more important as you hand over more complex, multi-step work — it isn't something that can be relaxed as trust accumulates. Every additional step in a complex task adds one more opportunity for ambiguity to creep into the instructions, so it's worth raising how specific your instructions are in step with increasing task complexity, rather than building trust first and letting precision slide afterward.

Full Content +

Anthropic announced on September 2, 2026, that Claude Cowork and Claude Code gained background computer use — on macOS 15 or later, Claude can now click, type, and open apps in a background window to complete desktop tasks you've assigned, while you keep using your computer for something else, without having to hand over your entire screen. This is a meaningful upgrade to computer use: earlier versions required giving Claude your full screen to work with, and there's now an option that doesn't interrupt what you're doing. It's currently limited to Pro and Max plans — Team and Enterprise plans don't have this feature yet.

How Background Mode Actually Works

Anthropic's documentation is explicit: on macOS 15 and later, Claude works in background windows so you can keep using your computer while it runs. Claude doesn't take over your pointer or keyboard, and it generally waits if you're in the middle of typing. Working in the background is the default on macOS 15 and later; if you'd rather watch Claude actually operate the screen, you can go into settings and change "when Claude requests access to an app" to "full control," switching back to the mode where your screen gets taken over. The first time in each session that Claude needs the full screen, it still asks for your permission before taking over.

Screen Control Is Claude's Last Resort, Not the Preferred Option

One design detail worth noting: screen control sits relatively far down the list when Claude decides which tool to reach for. If an MCP Server, a Bash command, a native connector, or the browser can accomplish the same thing, Claude prioritizes those channels; only when there's genuinely no other way to reach a particular app — legacy desktop software, an internal tool with no automation surface at all — does it fall back to operating the screen directly. That means background computer use fills a specific gap: work that has no path in other than "click and type the way a person would" — not a replacement for the more precise, more stable connectors or command-line tools that already exist.

Anthropic Itself Is Direct: These Guardrails Aren't Absolute

This is the line from the announcement most worth taking seriously. Anthropic's documentation states plainly that these guardrails are part of how Claude is trained and instructed, but they aren't absolute, and shouldn't be relied on as a substitute for blocking access to sensitive apps. The documentation goes further with concrete advice: don't grant computer use permission access to sensitive apps like banking, healthcare, or government; start with simple tasks like research or organizing rather than handing it a complex multi-step workflow right away; make sure your prompts are specific and carefully tailored to avoid Claude doing things you didn't intend. That's not boilerplate legal language — it draws a clear line: the safeguards reduce risk, but they're probabilistic in nature, not a guarantee.

A Trust Boundary of a Different Nature Than Regular Connector Access

Computer use carries a different kind of risk than Cowork's usual file reads/writes or connector-based data access. File operations go through permission checks; code execution runs in an isolated environment. Computer use, by contrast, runs directly on your actual desktop, and its reach is bounded by whichever apps you've already approved access to — meaning once an app is authorized, what Claude can do within that app is closer to "what a person actually sitting at your computer could do" than to something confined within a security sandbox. That's also why Anthropic specifically emphasizes that computer use's trust boundary is different from its other tools, and needs to be treated with a different degree of caution.

Current Limitations

This feature currently only supports macOS 15 and later, and is limited to Pro and Max plans — Team and Enterprise plans can't use it yet. The desktop app supports both macOS and Windows, but this specific background-window mechanism is currently macOS-only; if you use Claude Code via the command line, computer use there is also currently macOS-only. Your computer needs to stay powered on and the Claude Desktop app needs to remain open while it runs — consistent with the logic of any other Cowork task that needs a local environment.

What This Means for Your Work

If you have a piece of work stuck on "this system is GUI-only, no API, no CLI, the only way in is clicking around like a person," background computer use fills exactly that gap, and without tying up your entire afternoon on a machine you can't otherwise use. But before turning this on, it's worth honestly taking stock of the apps installed on your computer — particularly anything touching money, medical records, or government filings. Not because Claude will necessarily go near them, but because Anthropic itself says the trained-in guardrails aren't foolproof. The genuinely reliable line of defense is excluding those apps from the granted scope yourself upfront, rather than trusting after the fact that Claude will know on its own what to avoid. Starting with simple, redoable tasks, rather than handing it a multi-step workflow with little room for error right out of the gate, matches the order of priorities Anthropic's own guidance actually recommends.

Sources: Let Claude use your computer in Cowork - Anthropic Help Center
Ask a Question
Please enter at least 10 characters
Related Articles
After Your Account Moves to the New Claude Experience, Where Did Cowork's Global Instructions and Storage Folder Go?
advanced · Sep 21
Five Things You Still Can't Do After Cowork Merges Into Chat — Especially the Incognito One
advanced · Sep 21
A Note for Healthcare Teams: Claude Cowork Isn't Covered Under Anthropic's HIPAA BAA, No Matter Your Plan Tier
advanced · Sep 10
What Does the Effort Control in Cowork Actually Adjust? It's Not the Same Thing as Switching Models
advanced · Sep 10
Related News
More Related Topics