AgentsAutonomy & tool use
Anthropic makes cloud sandboxes the default for Claude Cowork tasks on Pro and Max plans
Starting October 6, new Claude Cowork tasks on Pro and Max plans run in per-session cloud sandboxes on Anthropic's servers, and the local-only option is gone. Engineering lead Felix Rieseberg cites battery, reliability and phone access, a shift from his earlier local-first argument.
From October 6, new Cowork tasks on Pro and Max plans run on Anthropic's servers rather than on the user's computer, and the setting to keep work only on the computer has been removed. Tasks already running locally stay local until they finish. Rieseberg said affected users were told by email and an in-app notice. [2] [1] [5]
In March, Rieseberg argued that the local machine is undervalued and that AI agents should have their own computer. He now says the local VM cost disk space, battery and performance, and that work stopped when a laptop closed. In his account, the cloud version fixes these problems and makes phone use possible. [3] [1]
In Anthropic's documented design, each session gets its own temporary sandbox that is destroyed when the session ends. Outbound traffic must pass through an allowlisting proxy, credentials expire within hours, and connector tokens never enter the sandbox. Cloud tasks can read local files only in connected folders, and only while the desktop app is open. Reading a local file becomes a tool call that the desktop app carries out. [6] [1] [2]
Isolation limits where code runs, not what the agent reads. Untrusted email, documents and connectors are still routes for prompt injection, and network allowlists do not cover web fetch, web search or MCPs. An independent analysis also points to a new failure mode: sessions can end up half-connected when the desktop app goes offline. [8] [7]
Anthropic's documentation describes isolated sandboxes, a mandatory egress proxy and short-lived credentials.
Read the full assessment
Implication: security controls shift from endpoint tools to vendor infrastructure, and task data leaves the device, so teams should review admin and privacy settings.
Sources are gathered; writing the dossier now.
Executive brief
Starting October 6, 2026, new Claude Cowork tasks on Pro and Max plans run on Anthropic's servers instead of on users' computers. The "Only on your computer" setting is gone (Claude Help Center). In March, Cowork's engineering lead Felix Rieseberg said Silicon Valley undervalues the local computer. Now he says the cloud version fixes battery drain, stops work from halting when a laptop closes, and makes phone use possible (Simon Willison). The tradeoff: more convenience, but transcripts and execution now live on Anthropic's servers instead of the user's machine.
What changed and event timeline
Local-first case
Rieseberg argued that AI should have its own computer, that the local machine is undervalued, and that a VM sandbox reduces approval fatigue ().
Containment design published
Anthropic described Cowork's local VM, which uses Apple Virtualization and Windows HCS, with credentials kept on the host. It also said EDR tools cannot inspect activity inside the guest VM ().
Pre-migration criticism
Artificial Corner warned that task transcripts would move to Anthropic's servers and that cloud tasks stop being files users own. It suggested Claude Code as a local alternative ().
Rieseberg explains the shift
He said both model inference and the VM now run in the cloud, with one sandbox per session. On X, he said affected users got an email and an in-app notice (;).
Cloud becomes the default
New Pro and Max tasks run in the cloud. Tasks already running locally stay local until they finish ().
Capabilities and access
- Model: none of the reviewed sources names a specific Claude model or version.
- Plans: new tasks on Pro and Max run in the cloud.
- Cross-device: sessions follow the account across desktop, web and mobile. Scheduled tasks no longer need the computer to be on.
Read the full section
- Model: none of the reviewed sources names a specific Claude model or version.
- Plans: new tasks on Pro and Max run in the cloud. On Team and Enterprise, Cowork is in beta on web, mobile and the Chrome panel wherever an admin turns it on (Help Center).
- Cross-device: sessions follow the account across desktop, web and mobile. Scheduled tasks no longer need the computer to be on.
- Local files: a cloud task can reach local files only in folders the user has connected, and only while the desktop app is open.
- Not on web or mobile: local connectors and plugins. Computer use is still in beta.
Technical analysis for researchers and developers
The architecture overview describes the two designs: No reproducible security evaluation of either design has been published.
Read the full section
The architecture overview describes the two designs:
- Old (local): the agent loop ran on the device. Code ran in a Linux VM with egress filtering, syscall restrictions and per-session user isolation. Local MCP servers had direct access.
- New (cloud): the agent loop and code execution run in a temporary sandbox for each session, which is destroyed when the session ends. By default it cannot reach private addresses. All outbound traffic goes through a mandatory proxy outside the sandbox, which only lets allowlisted destinations through. Credentials are session tokens that expire within hours. Connector tokens stay on Anthropic's servers and never enter the sandbox.
- Local file access: in the new design, reading a local file is a tool call that the desktop app carries out, over connections brokered by Anthropic (Simon Willison).
No reproducible security evaluation of either design has been published.
Claims and evidence
- The local VM cost disk space, battery and performance, and work stopped when the laptop closed — Vendor-reported ()
- Sessions are isolated from each other; egress goes through a proxy; credentials are short-lived — Vendor-documented (); no independent audit found
- Cloud data is not used for training
Read the full section
| Claim | Status |
| The local VM cost disk space, battery and performance, and work stopped when the laptop closed | Vendor-reported (Rieseberg via Willison) |
| Sessions are isolated from each other; egress goes through a proxy; credentials are short-lived | Vendor-documented (architecture overview); no independent audit found |
| Cloud data is not used for training | Stated for Team and Enterprise commitments (overview). For consumer plans, retention depends on the "Help Improve Models" privacy setting (Help Center) |
| Cloud tasks keep working without the computer | Disputed for tasks that need local files or the browser (Artificial Corner) |
Context and prior work
- Original design: at launch, Cowork was a research preview for Max subscribers on macOS.
- Three ways to place an agent: an independent analysis compares a local VM, a cloud sandbox per session (new Cowork), and an always-on cloud computer (OpenAI's "dots") (Redreamality).
- Earlier argument: in March, Rieseberg pointed to a practical problem with cloud agents.
Read the full section
- Original design: at launch, Cowork was a research preview for Max subscribers on macOS. It worked on a user-chosen folder inside an isolated VM (VentureBeat).
- Three ways to place an agent: an independent analysis compares a local VM, a cloud sandbox per session (new Cowork), and an always-on cloud computer (OpenAI's "dots") (Redreamality).
- Earlier argument: in March, Rieseberg pointed to a practical problem with cloud agents. Login systems may lock accounts when they see the same user signed in from different places at once (Latent Space).
Limitations, safety and contested findings
- Sandboxing doesn't stop prompt injection. Isolation limits where code runs, not what Claude reads. Untrusted email, documents and connectors remain the attack surface.
- New failure modes: local MCP servers still run on the device. Sessions can end up "half-connected" when the desktop app goes offline (Redreamality).
- Privacy and lock-in: transcripts move off the device, and moving tasks to competing tools gets harder (Artificial Corner).
Read the full section
- Sandboxing doesn't stop prompt injection. Isolation limits where code runs, not what Claude reads. Untrusted email, documents and connectors remain the attack surface. Network allowlists also don't govern web fetch, web search or MCPs (Redreamality). Anthropic itself warned at launch about destructive actions and prompt injection (VentureBeat).
- New failure modes: local MCP servers still run on the device. Sessions can end up "half-connected" when the desktop app goes offline (Redreamality).
- Privacy and lock-in: transcripts move off the device, and moving tasks to competing tools gets harder (Artificial Corner).
Business and practitioner implications
- Security teams: the main controls are now the vendor's egress proxy and token scoping, not endpoint tools.
- Privacy-sensitive users: check the "Help Improve Models" setting. Anyone who needs local execution can move workflows to Claude Code (Artificial Corner).
- Agent builders: this is a vendor that publicly argued for local-first moving to a cloud sandbox per session, which suggests where the field is heading.
Read the full section
- Security teams: the main controls are now the vendor's egress proxy and token scoping, not endpoint tools. Review the architecture overview and admin settings, including the MDM keys that can disable local MCP servers.
- Privacy-sensitive users: check the "Help Improve Models" setting. Anyone who needs local execution can move workflows to Claude Code (Artificial Corner).
- Agent builders: this is a vendor that publicly argued for local-first moving to a cloud sandbox per session, which suggests where the field is heading.
Sources
Read the full section
- Simon Willison: Quoting Felix Rieseberg
- Felix Rieseberg on X
- Claude Help Center: Use Claude Cowork on web, desktop, and mobile
- Claude Help Center: Claude Cowork architecture overview
- Anthropic Engineering: How we contain Claude across products
- Latent Space: Why Anthropic Thinks AI Should Have Its Own Computer
- VentureBeat: Anthropic launches Cowork
- Redreamality: Claude Cowork Moves Execution to the Cloud
- Artificial Corner: If You Use Claude, Do This Before October 6