Back to Explore
NewsVibeFix 编辑部Updated Oct 7, 2026

Close Your Laptop, the Agent Keeps Working: Claude Cowork Moves Its Sandbox to the Cloud

Anthropic is moving Cowork's execution environment from a local VM to per-session cloud sandboxes: work survives a closed laptop and can be driven from a phone. This is more than an architecture upgrade — the agent "runtime layer" is becoming cloud utility, and solo teams must update their workflows and security assumptions.

A data center aisle of server racks glowing blue — the cloud where agent sandboxes now live

Late on October 5, Simon Willison relayed a short message from Anthropic on his blog — brief, but pointing at a major turn: Claude Cowork is moving its execution environment off your laptop and into the cloud.

The message came from Felix Rieseberg, who leads Cowork engineering at Anthropic. He laid out the before-and-after: the old version ran model inference in the cloud but executed tool calls in an "Anthropic-provided VM we shipped to your computer." The design was motivated by capability, safety, and isolation — only data you explicitly added to a session got mapped in. But users quickly felt the cost: the local VM ate disk, drained battery, and slowed the whole machine. Worse, closing your laptop means the work stops.

The new version moves both inference and the VM to the cloud. Each session gets its own sandbox, with no shared state between sessions; when the cloud VM needs something on your device (like a file), the desktop app performs that file-access tool call. According to Rieseberg, the change resolves a long list of complaints: Cowork becomes usable from a phone, work no longer dies when you close the lid, and nobody pays a battery tax for the VM anymore.

Why this deserves its own story: it is not "a feature shipped." It marks a turn in the general-agent product roadmap — the execution layer is leaving your computer.

From "a VM on your machine" to "a sandbox in the cloud"

To feel the weight of the shift, recall what Cowork is. In January, Anthropic launched Claude Cowork as a research preview, positioned as "Claude Code for the rest of your work" — bringing Claude Code-class agent capabilities to non-coding work. It was initially limited to Max subscribers ($100 or $200 per month) inside the macOS Claude Desktop app; a January 16 update extended it to $20-per-month Claude Pro.

Willison's hands-on review in January nailed it in one line: Cowork is a general agent well positioned to bring Claude Code's capabilities to a wider audience, but prompt injection risks remain. The original architecture was very "Anthropic": Rieseberg has said on a podcast that Anthropic believes AI needs access to the user's local computer — local means data never leaves your device, and the VM provides isolation. Nine months later, reality punched back: every complaint was about the cost of the local VM. Disk, battery, performance — and that most vivid detail: close the laptop, the work stops.

So Anthropic made the choice every big company eventually makes when product and security collide: make the product good first. Cloud sandbox, per-session isolation, and a desktop app that only "hands over files" — a clean three-part design.

Note the timeline: at launch in January, Cowork was on team "local VM"; by October it had switched to team "cloud sandbox." In nine months, Anthropic overturned the technical narrative it had told on podcasts ("AI needs access to your local computer"). That speed of self-reversal shows agent architectures haven't converged — a workflow you build on "local-first" this year may need rewriting next year. The only designs that won't expire are location-independent ones: sessions that detach and resume.

Why this matters more than it looks: phones, closed lids, unbroken sessions

On the surface, these are three UX fixes: usable from a phone, survives a closed lid, saves battery. One level deeper, this is the usability threshold for general agents.

Coding agents can live with "runs in my terminal," because programmers sit at their computers anyway. But Cowork's ambition is "the rest of your work" — expense reports, resume screening, email follow-ups, crash-log triage. These tasks share one trait: they happen in your life, not at your desk. You remember something on the subway, say one sentence to the agent from your phone, and find it done when you're back — that is the product shape of a general agent. And its precondition is decoupling the execution environment from your device: the task lives in the cloud; you just drop by occasionally.

Rieseberg shared a telling detail on the podcast: he has Cowork dig through system crash logs, filter fixable bugs, and schedule multiple Claude instances to patch code separately — no bug tracker, no ticketing system. The categorizing, prioritizing, and assigning that "middleware" used to do now happens inside the agent's own process. The intermediary layer of the SaaS era is being eaten by agents — and the precondition is that the agent itself has a "home," one that doesn't depend on your laptop lid being open.

One easily missed signal: Cowork itself was built inside Anthropic in about ten days — Rieseberg told the "10-day" story on a podcast. A usable general agent grown from Claude Code's foundation in ten days means the "runtime layer" is getting thin, and thin things get platformized. When Docker, OpenAI, and Anthropic are all building cloud sandboxes at once, the sandbox stops being a moat and becomes utility.

Anthropic is not alone here. At the WeAreDevelopers congress in late September, Docker launched Docker Cloud Sandboxes — "secure, isolated AI agent execution" — alongside Kits, an open spec for packaging agentic sandboxes. Over at OpenAI, Willison was already running experiments in a Codex Remote (cloud) session in early October. Everyone is moving the sandbox to the cloud. Cowork's move simply takes down the "local-first" flag Anthropic itself planted in January and replants it in the cloud.

The security ledger: per-session isolation is progress, but the data boundary moved

To be fair, the new architecture is a security step forward: each session gets its own sandbox, with no shared state — basic multi-tenant hygiene, cleaner than "one VM for all sessions." Confining local-file access to tool calls performed by the desktop app narrows the privilege of "touching your files" to one explicit channel.

But the boundary moved, and the risk moved with it. Under the old design, your data boundary was physical: the VM lived on your machine; power off, and it's gone. Under the new design, your session state, intermediate files, and the full context of tool calls live in Anthropic's cloud. The thing you trust shifts from "my own machine" to "the vendor's isolation implementation."

Cowork's security track record counsels against optimism. In January, Prompt Armor demonstrated a bypass: Cowork only allowed outbound HTTP to a fixed domain allowlist, to defend against prompt-injection exfiltration — but Anthropic's own API domain was on the list, so attackers had the agent upload visible files to the Files endpoint under the attacker's own API key and retrieve them later. Allowlist defenses that "look strict" keep finding creative bypasses once an agent is in the loop.

Another risk worth isolating is the "desktop app handles file access" design. It sounds well-scoped: every touch of a local file passes through one explicit gateway. But once the gateway becomes the single trust anchor, it becomes the thing attackers most want to fool — prompt injection doesn't need to break the sandbox, only to convince the file-passing channel to pass one more file. For one-person teams, the audit focus should move from "what happened inside the sandbox" to "which files were passed into the sandbox, and who approved it."

Willison's "lethal trifecta" from last year still applies: access to private data, exposure to untrusted content, and the ability to communicate externally — an agent with all three is high-risk. Moving to the cloud removed none of the three; it only swapped the far end of "external communication" from your laptop to a cloud sandbox. For anyone running sensitive workflows through Cowork, the question changes from "do I trust this computer" to "do I trust this session's isolation, and is every cross-boundary file access visible and auditable."

A judgment for one-person teams: where the moat moves after the runtime goes cloud

A final judgment, aimed directly at VibeFix readers.

Over the past year, the vibe-coding narrative has been "one person + AI = one team." Hidden inside that formula is an assumption: the AI lives on your computer, and you babysit it. Cowork's cloud move, together with Docker Cloud Sandboxes and Codex Remote, is turning the "runtime layer" into standard cloud utility: sandboxing, isolation, persistent sessions, and phone reachability will all become out-of-the-box infrastructure.

When the runtime becomes utility, the moat moves up the stack. Rieseberg dropped a line on the podcast worth savoring: skills are just text files — and memory is often just text files too. Anthropic's internal read on Cowork is that differentiation beyond the model lives in workflows, skills, alignment, and taste — the answer to "when execution becomes nearly free, what becomes the bottleneck."

For one-person teams, the operational implications are threefold. First, stop designing workflows around "the agent must run on my machine"; design for sessions that detach, resume, and can be picked up from a phone — surviving a closed lid is not a feature, it's the new baseline. Second, put your compounding assets in text: skills, memory, and decision logs as files are the only things that travel across sessions and platforms. Third, move your security budget with the boundary: you used to guard against "don't lose this laptop"; now guard against "don't over-permission this cloud session" — least privilege, visible cross-boundary access, and routine session cleanup will become the standard checklist for solo teams.

There's also a cost ledger. Always-on cloud sessions mean the agent can keep working while you sleep — metered cloud sandboxes plus unattended agents are exactly the combination Willison warned about in his "hard budget caps" piece three days earlier (which VibeFix covered). The conclusion still applies here: give every cloud session a budget that stops work when spent, instead of reading the bill afterward. A solo team has no dedicated FinOps; your budget cap is your FinOps.

It took Anthropic nine months to go from "AI needs your local computer" to "your computer is just a remote control." That U-turn is one of the most important signals in agent products this year: the battle for general agents won't be won on model parameters, but on who first makes "say the word, close the lid, come back to done" an everyday routine.

Sources

Browse projectsPublish your project

Related articles

Data visualization charts of a global developer survey with code elements
News
Stack Overflow 2026 Survey: AI Adoption Plateaus, Trust Turns Conditional

Stack Overflow published its 16th annual developer survey on October 6: 30,000+ respondents across 169 countries. 66% use coding assistants, 26.2% already run automated agent workflows; but trust has shifted — nearly half only trust AI when they can verify its work, and just 6.6% would entrust it with important decisions; 30% say workplace AI use is left to individual discretion. The official snapshot of vibe coding penetration in 2026.

Industry TrendsAI CodingLearning & Career
Concept illustration of a robot holding a digital ID card with a shield verification badge, symbolizing AI agent identity
News
AI Agents Get Their Own 'Sign in with Google': AgentMail Launches AgentID

AgentMail launched AgentID on October 6: agents log in to third-party apps using their own email as an OpenID Connect identity. The verification-code step disappears, one authorization lasts 180 days. Identity may be the real watershed between agent toys and agent production.

AI CodingProduct LaunchAuthentication & Access