GitHub Copilot CLI and App Add Computer Use in Public Preview, Letting the Agent Operate macOS and Windows Desktop Apps
GitHub put computer use into public preview in Copilot CLI and the Copilot app on macOS and Windows; it is off by default and asks approval before controlling an app.
Overview
GitHub announced on October 1, 2026 that computer use is now available in public preview in GitHub Copilot CLI and the GitHub Copilot app on macOS and Windows. The feature lets Copilot operate desktop applications on a user’s behalf, extending the coding agent beyond terminals, editors and APIs.
What We Know
- What it can do. According to the GitHub changelog, Copilot can read accessible app content and visual context, click controls, enter and edit text, press keys, scroll, drag, and navigate workflows across applications. GitHub’s documentation says it reads content through the operating system’s accessibility tree or screenshots when visual context is needed.
- Target use case. GitHub says the feature expands automation to workflows in legacy and GUI-only software that do not provide an API, command-line interface, or MCP integration, per the changelog. Examples it gives include summarizing notifications in a browser and updating content in a presentation.
- Enabling it. In Copilot CLI, the changelog says to run
/computer on, with/computer showto check status and/computer offto disable it. In the Copilot app, users open Settings, select Computer Use and turn on Enable Computer Use, or use/computer on. - Off by default. The documentation states that computer use is disabled by default and that it follows the tool permission settings of the Copilot surface in use. Users can grant access for the current session, save the approval for future sessions, or deny it.
- Approvals and admin control. The changelog says Copilot asks for approval before controlling an app, users can review or reset apps they chose to always allow, and organization-managed settings can disable the feature. The documentation adds that enabling it locally does not override an enterprise policy, and that a saved Always allow decision is stored locally and applies to both the CLI and the app on the same computer.
- Interrupting. Per the documentation, an active operation can be stopped by pressing Esc twice in the CLI, or by clicking Stop or pressing Esc in the app. On macOS, the changelog says the feature guides users through the required Accessibility and Screen Recording permissions.
Stated Limitations and Risks
GitHub’s documentation is explicit about the risks. It says computer use can select the wrong control or enter text in the wrong location, and states: “Computer use can automate interactions across desktop applications, but it also introduces security risks.” It adds that ambiguous instructions or unexpected on-screen content may cause unintended actions affecting a user’s device, data or connected accounts. It advises avoiding Always allow for applications that contain sensitive information or support high-impact actions, and says that if an API, MCP server, terminal command, filesystem tool or dedicated browser tool can complete a task directly, that tool typically gives more structured and predictable results.
What We Don’t Know
The sources do not say when the feature will leave public preview, whether Linux will be supported, or how often the agent misclicks in practice. The documentation notes only that computer use is in public preview and subject to change.
Context
The move follows Copilot app changes The Machine Herald previously reported, including local sandboxing that is also off by default. In March, The Machine Herald reported that Anthropic launched a research preview letting Claude operate Mac desktops.