Claude computer use is now available to Claude Pro and Claude Max subscribers, Anthropic said Monday, allowing the artificial intelligence assistant to control a user’s computer to complete tasks autonomously.

The feature is currently limited to computers running macOS. Anthropic described the release as a research preview, noting that the company is collecting early feedback to improve the tool.

How Claude Computer Use Works

Claude first searches for available connectors with apps such as Google Calendar or Slack to complete a given task. If no connector is available, Claude performs the task manually by moving the cursor, typing, scrolling, and clicking, as a human user would.

The assistant can interact with web browsers, developer tools, and open files. Notably, Claude will always request user permission before executing any action. Users can stop the assistant from performing a task at any time.

Cybersecurity Risks and Safeguards

Granting an AI model access to a computer introduces cybersecurity risks. Experts have noted that agentic AI systems can take significant actions quickly and with little warning. Malicious actors can also hijack such tools to access personal data and systems without authorization.

Anthropic said it implemented safeguards against prompt injection attacks and other vulnerabilities. The system scans for these threats automatically as new capabilities are added. However, Anthropic also issued a warning to users, advising against using the feature with apps that handle sensitive data. Several such apps are disabled by default.

Integration with Dispatch

Anthropic said Claude computer use works alongside Dispatch, a companion feature that lets users assign tasks to Claude from a mobile phone. Supported tasks include checking email each morning, or opening a Claude Cowork or Claude Code session.

Together, the two features allow users to automate workflows even when they are away from their computers. Anthropic provided examples such as generating a morning briefing or running automated tests.

Competitive Context

The release follows the rapid growth of OpenClaw, an open-source framework that enables AI models to execute commands on computers and connected systems. OpenClaw has generated a broad ecosystem of tools, referred to as “claws.” Nvidia last week introduced NemoClaw, its own framework for deploying OpenClaw with built-in security settings.

Anthropic acknowledged that complex tasks may not complete successfully on the first attempt. The company said it is releasing the research preview to identify areas requiring further development before a wider rollout of the AI-driven capability.