Anthropic lets claude loose on your laptop—then phones you the results

Anthropic just handed its ai agent the keys to your desktop. Claude Coworker, released in limited beta on Wednesday, can boot up before you pour coffee, rifle through overnight mail, pull the metrics your boss wants, and ping your phone with a three-bullet summary—no human in the loop until the exit sign flashes.

The shift from chatty assistant to silent operator

Where vanilla Claude waits for prompts, Coworker runs on scheduled intent: users draft a goal (“check Gmail for invoices, paste totals into Slack at 08:00, alert me only if>$10 k”) and choose a cadence—once, daily, or when a trigger file lands. The model then spawns a containerized browser, logs in via encrypted credentials stored locally, and executes the chain. A push notification lands on iOS or Android with screenshots and a one-tap “approve/abort” button. The phone never stores session cookies; the desktop instance self-wipes after idle timeout.

The demo I watched live in San Francisco felt almost mundane—until the speed sunk in. Claude opened seven browser tabs, scraped a Salesforce dashboard, built a pivot table, and drafted the Slack message in 92 seconds. A senior engineer admitted the same workflow takes her 24 minutes and two espressos every morning. Multiply by 5 000 early-access testers already granted keys and you get a sense of why Anthropic’s support queue ballooned overnight.

Your files are one mis-click away from a bot

Your files are one mis-click away from a bot

Convenience, however, ships with a side order of dread. Because Coworker operates inside the user’s own Chrome profile, it can—if instructed—open Finder or File Explorer. Anthropic’s own red-team found three scenarios where a prompt injection hidden in an email could coax the agent into exfiltrating local tax PDFs to a remote server before the notification even pops. Their mitigation: a hard gate. Any read/write request outside the pre-approved domain list triggers an instant pause and a red banner that demands biometric re-authentication.

Still, the company concedes the risk surface is novel. A passive chatbot leaks nothing unless you paste secrets; an active agent already inside your SaaS perimeter can cascade small breaches into large ones. Anthropic therefore ships Coworker with a “sensitive folder” blacklist pre-loaded: anything labeled “finance”, “medical”, “legal” or “tax” is blocked by default. Users can whitelist, but only after typing a 32-character passphrase displayed once at setup. The firm also recommends running the feature inside a separate macOS account or Windows VM—advice most consumers will promptly ignore.

Competition races toward the same cliff

Competition races toward the same cliff

OpenAI’s code-interpreter-plus-plugins combo already handles file I/O, while Google’s Project Astra promises cross-device memory later this year. Neither yet offers unattended scheduling, giving Anthropic a narrow window to claim the “agent” narrative. Enterprise pilots—Slack, Asana, Notion, and a major logistics company I cannot name—pay between $60 and $120 per seat monthly for the privilege, 6× the consumer ChatGPT Plus tariff. The margin funds the beefier infrastructure: each Coworker task spins a dedicated virtual core for privacy isolation, a cost Anthropic absorbs until volume scales.

Regulators are circling. The Italian Garante asked for a technical brief within ten days; the French CNIL hinted at classifying persistent ai browsing as “automated profiling” under GDPR. Anthropic’s legal team argues the user remains the data controller because the agent runs client-side. The counter-argument: if the model decides which links to click, the autonomy line blurs. A draft EU ai Act amendment would force prior impact assessments for any system that can “initiate transactions without real-time human review.” Translation: Coworker’s current freewheeling model may not survive 2025 unaltered.

For now, access is gated behind a wait-list and a 15-minute safety video that 42 % of invitees skip, according to internal analytics. Those who persist receive a cryptic closing line: “Remember, Claude never sleeps—but you still can.” The joke doubles as disclaimer: if your laptop stays open and the agent encounters an edge-case loop, it will keep clicking until the battery dies or the CAPTCHA wall arrives. Early beta forums already host horror stories: one user woke to 1 800 duplicated Trello cards titled “TODO - fix later.”

Anthropic swears incident logs feed a nightly retrain, yet the fundamental trade-off remains. We are outsourcing not just labor but judgment—asking cloud code to decide what deserves our attention before we’ve sipped breakfast. The company frames it as democratizing a chief-of-staff; critics call it the fastest way to weaponize your own digital footprint. Either way, the 4 a.m. glow of an active Claude session is about to become the new status light of remote work. Just hope it remembers to lock the door after it leaves.