On September 2, 2026, Anthropic made it possible for Claude Cowork and Claude Code to run computer use in the background. On macOS 15 or later, you can keep working on something else while Claude opens apps, clicks and types. Computer use itself was available before, but if the AI needed the screen and input devices to itself, your own work had to stop in the meantime. This update shortens that wait. It does not remove the requirement to keep the device awake, nor the permissions needed to operate real apps.
An update that lets you keep using your Mac, and what it requires
According to Anthropic's official help page, on macOS 15 or later Claude runs in a background window and does not take over your pointer or keyboard. While you are typing, it generally waits until you finish. It is not a mechanism that forces simultaneous input in every situation, regardless of what you are doing.
If a task requires full-screen use partway through, Claude asks for permission the first time that operation is needed in the session. Whether a job can be completed in the background, or needs you to give up the screen midway, depends on the task. That difference affects how much work you can actually run in parallel.
The Cowork help page describes the feature as a beta, available to Pro and Max subscribers. Team and Enterprise plans are not eligible for computer use. Cowork as a whole being available on organizational plans is a separate matter from whether this feature is. Computer use itself supports both macOS and Windows, but the official explanation of background operation covers only macOS 15 or later.
To use it, enable computer use in the desktop app's settings. According to the Claude Code instructions, macOS Accessibility and Screen Recording permissions are also required. Once enabled on macOS 15 or later, background operation is the default. Turning the feature on is a separate step from choosing the background mode for each operation.
Why Claude prefers dedicated tools over clicking
Cowork uses a connector first if one is available. Connectors are integrations that interact directly with services such as Gmail and Slack. For work they cannot reach, it moves on to the built-in browser or a selected Chrome and operates the screen by clicking directly.
This order of priority exists because screen operation, however advanced it looks, is not always the best option. In its March 23 announcement introducing computer use, Anthropic also explained that work done through the screen is slower than direct integrations, and that complex tasks may need retries. Moving to the background helps people get other work done, but that alone does not mean click-based work has become faster or more accurate.
In Claude Code, the policy of preferring dedicated tools also shows up in permissions. In the per-app permissions table, computer-use access to browsers is view-only, and terminals and IDEs are limited to clicking and scrolling, with typing and keyboard shortcuts not allowed. The design has shell work go through dedicated tools such as Bash. It does not mean Claude Code can no longer run commands in the terminal.
There is also another route for the browser that reduces interference with the user. Cowork's built-in browser runs separately from the browser you normally use. Saved logins are not shared unconditionally; you choose which ones to bring in. Whether you ask for work on pages in your own Chrome or hand it to Claude's browser changes what information is exposed and where the work happens.
Screen operation is useful for apps that have no dedicated integration or API and require pressing buttons on screen. An API is a gateway through which programs request processing from one another, and some software does not offer one. Being able to hand off such work, combined with being less likely to interfere with your input, widens the range of everyday desktop tasks where this is useful.
How cloud execution differs from background operation
Even when Cowork's processing runs in the cloud, access to your local PC has separate conditions. According to the official architecture overview, processing and code execution in a cloud session proceed on Anthropic's servers, while requests that use local files and the like reach the device through Claude Desktop. If the app is offline, that device cannot be accessed.
Background operation, cloud execution and code isolation each change different conditions.
| Feature / mechanism | What changes | Remaining conditions / limits |
|---|---|---|
| Mac background operation | Operates apps without taking over the user's pointer or keyboard | Requires macOS 15 or later. The device must not sleep, and Claude Desktop must stay open |
| Cowork cloud execution | Runs agent processing and code execution on Anthropic's servers | Cannot access a local device that is offline |
| Code isolation environment | Restricts the environment where code runs and what it can access | Reading and writing through approved external tools, and permissions to operate real apps, are managed separately |
In other words, the fact that Claude does not occupy your screen does not mean on-screen work continues when you close your PC. Computer use requires the device to be awake and the desktop app to be open. You need to distinguish between work that can be completed entirely in the cloud and work that operates apps on your own machine.
The scope of isolation also differs. In the existing locally run Cowork, agent processing runs on the device and code is executed in an isolated Linux virtual machine. Cloud sessions have a temporary isolated environment on the server side. Both descriptions concern the environment where code runs; neither means that all the real apps Claude operates are moved inside it.
Understanding this distinction lets you tell apart behavior that looks the same, "AI working behind the scenes," in terms of dependence on the device and the scope of permissions to grant. Moving to the background changes how input is used, while moving to the cloud changes where processing runs.
Even if the screen isn't occupied, the effects of actions remain
Anthropic's safety guide states clearly that computer use has no isolated environment separating Claude from the actual apps. Even if code is run in isolation, what Claude can read and change through the tools it is permitted to use is a separate question.
For example, clicking a link inside an app you have permitted may open another app. Even if Claude can be prevented from viewing that other app, the act of the link opening cannot necessarily be stopped. Per-app permissions do not guarantee that the effects of an operation stay within that app.
Reading the screen also carries a risk of exposing information. Claude understands content through screenshots, so sensitive information on display may come into view. In addition, prompt injection is an attack that steers Claude with malicious instructions embedded in emails or web pages. Anthropic provides per-app permissions, blocklists and attack detection, but does not claim the defenses are perfect.
When people can keep working on other things, the time they spend watching Claude can shrink. To make the most of that benefit, you need to narrow what you hand over beforehand. Limit the working folders and permitted apps, and decide when you will check the finished output. If you confuse getting your screen back with not needing to check the results, the reduced waiting time may turn into rework later.
To measure practicality, look at how often people are interrupted
What this update directly changes is that you can keep working on the same Mac while Claude handles apps. The March announcement showed a use in which you give instructions from a smartphone via Dispatch and have the PC work while you are away. This time, it becomes easier to use for parallel work with someone sitting at the PC.
For example, you might hand off a routine check in an app with no dedicated integration while you write a document. But if full-screen permission is requested frequently, or results need a lot of correction, the time saved will be less than expected. Beyond whether the AI finished the task, you should look at how many times the person was interrupted and how much they had to fix.
This is a different yardstick from benchmark success rates. Even if Claude's processing takes the same amount of time, there is a benefit if your own work moves forward in the meantime. Conversely, running in the background is not by itself a reason to judge the automation to be of high quality.
If you try it on Pro or Max, start by picking a small task you actually repeat, and compare the time to completion with the time you spent on approvals and corrections. If you can reduce interruptions while keeping up result checks without strain, desktop apps without integrations can also become targets for everyday delegation to AI.
