Back to Explore
NewsVibeFix 编辑部Updated Oct 6, 2026

Cua Spaces: Giving AI Agents a Desktop You Can Watch and Take Over

On October 2, Cua — founded by a former Microsoft researcher — launched Spaces: a free Mac app that lets AI agents operate software on a "shared desktop" you can watch in real time and take over at any moment. Its boldest feature is "app teleportation": moving your signed-in app session straight into the agent’s sandbox, no repeated logins. The desktop-agent era was never waiting on better models — it was waiting on supervisable execution environments.

Illustration of the Cua Spaces shared desktop: an AI agent collaborating with a user on the same screen

What happened

On October 2, Cua launched Cua Spaces: a free Mac app built for running AI agents on the desktop. The core design is disarmingly simple — the agent operates software on a "shared desktop" where you can watch its cursor move in real time, grab control with your own mouse at any moment, and hand it back.

The most interesting feature is "app teleportation." The biggest friction for desktop agents is login: asking an agent to sign into your email, dashboards, and SaaS tools from scratch is both tedious and risky. Spaces lets you move an already-signed-in app session — along with selected files and state — directly into the agent's sandbox. Before transfer, an explicit consent flow lists the app, files, and state involved; sensitive items require a separate opt-in, and macOS may ask for Touch ID or a password.

A Space is fundamentally a desktop: a local container or VM, a cloud sandbox, or a real machine you own that is registered with the system. Mac comes first; Linux images can run too. Spaces is free and source-available (FSL-1.1-MIT, converting to MIT two years after shipping), while the underlying Cua Driver is MIT-licensed.

Who is behind it

Founder Francesco Bonacci is a former Microsoft researcher who, with research lead Dillon DuPont, built Windows Agent Arena — the benchmark that has agents complete 150+ tasks in a real Windows environment. In their 2024 paper, their Navi agent completed 19.5% of tasks versus 74.5% for unassisted humans. Bonacci left Microsoft in early 2025, built Lume (a tool for native macOS VMs on Apple Silicon), founded Cua in San Francisco that March, and joined Y Combinator's X25 batch.

That track record explains Spaces' pragmatic bet: not on "smarter models" but on "the computer the agent acts on." The model decides what the agent wants to do; the desktop decides what it can do — and the latter has been the bottleneck.

Why now

Desktop agents are having a moment. Just days ago, GitHub put Copilot Computer Use into public preview — Copilot can now look at the screen and click controls. Microsoft is pushing a unified Copilot desktop app too. But big-tech offerings are tied to their own ecosystems: Copilot's desktop is Copilot's desktop.

Cua takes a different road: packaging the "supervisable desktop execution environment" as infrastructure anyone can use. No model lock-in, no cloud lock-in, not even machine lock-in — a Space can be your own Mac, your own Linux server, or your own cloud. Pro and Teams editions are reportedly on the way, aimed at shared team machines, session handoff, and admin controls.

There is also context: 2026 has seen a string of agent security incidents (remember the April agent that deleted a production database?). Cua's documentation repeatedly stresses permission boundaries: anyone controlling the destination Space could theoretically use a teleported signed-in session, so it advises teleporting only into Spaces you own. Keyvault keeps sessions encrypted on the Mac and mediates access requests. These are product-design safeguards, not an independent security audit — but at least someone is designing the door carefully.

The VibeFix take

The weight of this story is not "yet another agent product." It answers a question vibe coders face daily: would you let an agent touch software you are logged into?

Today's mainstream answer is "no" — which is why people let agents write code but not log into dashboards, send email, or operate SaaS. Cua Spaces tries to change the answer to "yes, when it is visible, take-over-able, and permission-logged." If it works, the agent's working radius expands from "the code repo" to "the entire desktop," and the "one-person company" vision of vibe coding finally closes the loop.

The cooler side: no customer, usage, or revenue figures back this story yet, and the YC seed round's size and valuation are undisclosed. This is a beautiful product bet, not a validated answer. But the bet points the right way — in the desktop-agent era, infrastructure comes first.

Sources

Browse projectsPublish your project

Related articles

PromptGit concept art visualizing prompt version control
Guide
Treat Prompts Like Code: Prompt Version Control for Vibe Projects

Prompts in vibe projects live in code strings, admin text boxes, and docs — changed live, version unknown when things break. This guide shows how to treat prompts like code: a prompts/ layout, YAML frontmatter, semantic versioning, PR reviews, canary rollouts with one-click rollback, plus an evals baseline — and a real war story: one added sentence cost 12 points of classification accuracy.

AI CodingDeveloper WorkflowTool Tips
Pull request workflow illustration: a developer submits code while code windows pass check marks toward merge
Guide
After the AI Writes the Code: A Practical Code Review Workflow for Vibe Projects

The faster AI writes code, the more review matters. Four layers: diffs for logic (boundaries, errors, concurrency — plus auth, payments, SQL, encryption, secrets), runtime for behavior (type checks, lint, security scans go green first), AI for first-pass screening (a second model reviews, humans read only flagged parts), humans for the final call (AI never clicks merge). Includes commit norms, PR template, branch protection, rollback plans.

AI CodingDeveloper WorkflowTesting & Quality
Developer team collaborating on code
News
GitHub Was Built for Humans: Cloudflare Offers $25,000 in Credits to Rebuild Git for Agents

Cloudflare's Birthday Week blog makes the case plainly: GitHub was designed for humans writing code; the agent era needs the collaboration layer reinvented. Artifacts enters open beta with a repo for every agent, plus a developer competition — $25,000 in credits for first place, deadline October 14. This is the first time a major infra vendor has put 'infrastructure for agents writing code' on the table as a public proposition.

AI CodingDeveloper WorkflowIndustry Trends