The old Cowork shipped a sandboxed VM to your computer. The new one puts that VM in Anthropic's cloud, one sandbox per session. The stated reasons describe where consumer agent infrastructure is heading.
The most revealing line in Felix Rieseberg's explanation of the new Cowork is not about security, models, or pricing. It is about a laptop lid. "Also, people didn't love that closing your laptop means the work stops," he wrote, in a passage quoted by Simon Willison. That sentence explains the redesign better than any architecture diagram.
The original Cowork ran model inference in the cloud but executed the agent's actions inside an Anthropic-built virtual machine installed on your own computer. The new Cowork moves that machine to the cloud too. Every session gets its own sandbox. Your laptop becomes a window onto the work rather than the place where the work happens.
The common assumption has been that consumer agents should run locally where possible: on your hardware, under your control, close to your files. Cowork's reversal suggests a different priority. For an agent you hand real tasks to, the binding constraint is not where the compute sits. It is whether the work keeps going after you walk away, and whether running it drains your battery and fills your disk.
This piece follows that decision outward. It touches the trust boundary around your data, the new class of bugs that always-on sessions produce, the industry's appetite for agents that work unattended, and the question of who ends up owning the user once the sandbox lives on someone else's servers.
Users rejected the local VM for its costs, not for its privacy model
Start with what the old design got right. According to Rieseberg's account, Anthropic added the local VM "for capability, safety, and security reasons," and it worked by "mapping in just the data you explicitly added to your session." That is a careful design. The agent could act on your files, but only the files you handed it, inside a box that kept it away from everything else on the machine.
And people liked the results. In his words, "People loved what they were able to do with Claude." The capability was not the problem.
The problem was the cost of hosting that box. Rieseberg lists three complaints:
- Disk: a full VM takes real storage.
- Battery: running it while the agent works drains a laptop.
- Performance: the rest of your machine slows down while it runs.
Then comes the fourth, which is structural rather than a resource cost: closing the laptop stops the work.
Notice what is missing from that list. In the account as quoted, no one asked to keep the VM local because they wanted their data to stay on their own hardware. That may say more about Cowork's user base than about consumers in general. Still, it is a useful data point against the idea that local execution is something mainstream agent users actively value. For this audience, local execution was a tax they paid for the safety benefits. Once those benefits could be delivered elsewhere, the tax looked like pure overhead.
The pattern resembles what happened with many desktop applications over the past fifteen years. The local install was never the feature. It was the delivery mechanism. When a hosted version could match the capability without the maintenance burden, most users moved without much protest. Agents appear to be compressing that same transition into a single product cycle.
Local execution was always a half-measure, because the model never ran on your machine
There is a detail in the old architecture that the local-first argument tends to skip over. Even the "old" Cowork ran model inference in the cloud. The thinking happened on Anthropic's servers. Only the doing, meaning the tool calls that read files and ran commands, happened on your laptop.
So the data you mapped into the session was already leaving your machine whenever the model needed to reason about it. The local VM controlled where actions executed. It did not keep your content local. That makes the new design less of a philosophical break than it first appears. Anthropic is not abandoning local privacy. It is consolidating two halves of a system that were already split across a network.
In Wardley Mapping terms, the agent execution environment is sliding from "custom-built, shipped to each customer" toward "utility, run centrally." Shipping a VM to every user's computer is what you do when the component is new and you have no other way to provide isolation. Running thousands of sandboxes in your own data center is what you do once the component is understood well enough to operate at scale.
Meanwhile, the cases where local compute still matters look different from general consumer task work. Simon Willison recently ran an arithmetic experiment on local hardware, a DGX Spark, specifically "to explore the effect in a fully controlled environment." He drove it by pasting an image into a Codex Remote session. Local hardware was the subject of a controlled test. The agent session was remote.
That split is suggestive. Local compute is valuable when locality is the point: reproducibility, a specific open-weight model, hardware you own. The open-weight side keeps supplying reasons to want that. Latent Space notes that Reflection's new model is US-trained from scratch and that a segment of the market has been eagerly waiting for that. For the person asking an agent to organize a folder of receipts, though, locality was never the goal. Finishing the job was.
The trust boundary moved off your laptop, and that is mostly good news
The Trust Boundary Model asks a simple question: where does data cross from one trust level to another? Those crossings are where you inspect and enforce.
In the old Cowork, the critical boundary sat between Anthropic's VM and your host operating system. The VM was meant to see only what you mapped in. But it was still a guest on a machine full of other things: your browser sessions, your SSH keys, your environment settings, every app you had ever installed. Any weakness in that boundary exposed the whole computer.
In the new Cowork, the boundary moves to the moment you hand data to the session. Once uploaded or connected, the work happens in a sandbox that, per Rieseberg, belongs to that session alone. Your laptop is no longer part of the execution environment at all.
Why is that mostly good news? Because personal computers are messy places to enforce security. Ben Thompson recently disclosed that his computer got hacked, through a macOS vulnerability that Dutch officials warned was under active exploitation on systems where port 5900 was reachable from the internet. Thompson is about as informed a user as exists, and he still wrote that it was his fault. If his machine can be compromised that way, it is a poor foundation for an agent that runs commands.
The subtler risk is inheritance. A recent GitHub advisory describes a parser that checked only certain editor environment variables, so VISUAL was discarded before any vulnerability check ran, even though Git falls back to VISUAL when choosing an editor to execute. That bug is not in Cowork. It does show how easily a tool running on a real machine can pick up configuration nobody audited. A fresh cloud sandbox starts without your machine's accumulated settings, which removes a whole category of surprise.
The trade is concentration. You now trust that Anthropic keeps sessions isolated from each other and from its own systems. That is a narrower and more professionally managed boundary than your laptop. It is also one boundary protecting many users at once, so a failure there would affect far more people than a single compromised laptop.
Always-on agents trade battery bugs for continuity bugs
Moving the sandbox to the cloud solves the lid problem. It also creates a new class of things that can go wrong, and Anthropic's own release notes show what they look like.
The Claude Code v2.1.291 release, which shipped hours after Rieseberg's comments circulated, lists two fixes:
- A regression in 2.1.290 where cloud sessions could drop answers to permission prompts.
- A regression in 2.1.288 where the last messages of a session could be lost.
Claude Code is a separate product from Cowork, and nothing in the notes ties these bugs to the Cowork launch. But they are a preview of the failure modes that cloud-hosted, long-running sessions produce. On a local machine, the failures users notice are physical: fans spin, the battery drops, the disk fills. In the cloud, the failures are about continuity. Did the agent receive my approval? Did the final output survive the session ending? Is the work I left running still running?
The permission-prompt bug matters most here. On the Autonomy Spectrum, permission prompts are the mechanism that keeps an agent nearer the copilot end: it pauses, asks, and waits for a human. When the human is present at a laptop, a lost prompt is an annoyance you notice immediately. When the human has closed the lid and gone to dinner, which is the scenario the new Cowork is designed for, a dropped answer could stall a task for hours or leave someone unsure what the agent was actually authorized to do.
This is the real engineering burden of always-on agents. Persistence is not just keeping a process alive. It means guaranteeing that every handoff between a person who comes and goes and an agent that does not is recorded, delivered, and recoverable. The fact that Anthropic is shipping fixes for exactly these handoffs suggests the company knows that is where the hard problems now sit.
The industry wants agents that work while you are away, and those agents need a permanent home
Cowork's redesign does not stand alone. Meanwhile, the broader agent market is converging on the same assumption: that useful agents run unattended.
The Sequence's weekly roundup put it plainly: "AI is getting an expense account." It described the week as one of "persistent agents, enterprise ambitions, spatial intelligence, and billion-dollar funding rounds," and observed that "the industry increasingly wants permission to enter our workflows, operate our software, and complete the tasks we keep postponing."
Read that next to Rieseberg's lid complaint and the two describe the same thing from different angles. The tasks we keep postponing are, almost by definition, ones we do not want to watch. Nobody wants to babysit an agent through a two-hour data cleanup. The whole value proposition is that you hand it off and come back to a finished result.
A laptop is a bad host for that kind of work. It sleeps. It travels. It runs out of power. It shares resources with everything else you are doing. An agent that depends on it inherits all of those interruptions. Willison's experiment points the same way: the session he ran was a Codex Remote session, not something tied to the machine in front of him.
The pattern suggests a working definition for the current generation of consumer agents. They are less like apps you open and more like contractors you assign. Contractors need a place to work that does not disappear when you leave the room. Cowork's per-session cloud sandbox is Anthropic's answer to where that place should be. The expense-account framing adds a second implication: once agents spend money and complete tasks on your behalf, the infrastructure they run on stops being an implementation detail and becomes part of the trust relationship.
Whoever runs the sandbox owns the relationship
The Harness Hypothesis holds that the value in AI is not in the model but in the harness that connects the model to the world. Cowork's move is a harness move. The model was already in Anthropic's cloud. What Anthropic has now pulled in is the execution environment: the files, the tools, the running state, the session history.
That changes the competitive picture for anyone weighing Anthropic's agent infrastructure against alternatives. When the sandbox ran on your laptop, the session state lived on hardware you controlled. When it runs in Anthropic's cloud, the state of your ongoing work lives there too. Aggregation Theory predicts what follows: the platform that holds the user's ongoing work holds the user. Switching from one model to another is easy. Moving a set of half-finished, stateful agent tasks out of one hosted environment and into another is not.
This is where the self-hosted world matters. Open-source harnesses such as OpenClaw sit at the opposite pole: you run the agent environment yourself, on hardware you choose, and you carry the security and uptime burden that comes with it. Readers comparing OpenClaw alternatives against hosted options like Claude Managed Agents should see Cowork's decision as a clear statement of Anthropic's view. Its bet is that most users would rather rent a well-run sandbox than operate one.
The bet has a strong case. Rieseberg's account shows real users choosing convenience over local control when they had both. Thompson's compromised Mac shows how hard it is for individuals to secure the machines that self-hosting depends on. And the release-note fixes show that the operational difficulty of persistence is something a large vendor is better placed to absorb than a single user.
The counterweight is lock-in, plus concentration of risk. Neither argues against cloud sandboxes. Both argue for watching what Anthropic offers for exporting session state, and for self-hosted harnesses to keep competing on the one thing a hosted platform cannot easily offer: work that lives entirely on your own terms.
What to check before you let the agent keep working with the lid closed
For a power user, the practical question is not whether cloud sandboxes are good in principle. It is what changes in how you hand work to an agent that no longer lives on your machine.
A short checklist, built from the trust boundaries above:
- Treat every file you add as uploaded. The old Cowork mapped in just the data you explicitly added. That discipline still applies, and the consequence is clearer now: anything you add leaves your hardware for the length of the session.
- Decide approvals before you leave. Given that cloud sessions have had bugs that dropped answers to permission prompts, do not count on a perfect back-and-forth while you are away. Scope the task so the agent needs as few mid-run approvals as possible.
- Save outputs you care about. The same release fixed a bug where a session's last messages could be lost. Until continuity is proven over time, copy important results somewhere you control.
- Separate tasks into separate sessions. Each session gets its own sandbox. Use that isolation deliberately rather than piling unrelated work into one long run.
- Do not assume local equals safe. If you choose self-hosting for control, harden the host. Exposed services and inherited configuration are real attack paths, as both Thompson's incident and the VISUAL advisory illustrate.
The broader reading is straightforward. Consumer agent infrastructure is moving away from "run it locally to be safe" toward "run it remotely, in isolation, and keep it running." Anthropic did not make that shift because local execution failed technically. It made it because the people using the product wanted to close their laptops and have the work continue. That preference, more than any benchmark, is shaping where agents will live.
/Figures
| Component | Old Cowork | New Cowork |
|---|---|---|
| Model inference | Cloud | Cloud |
| Tool-call execution VM | Anthropic VM on your computer | Cloud |
| Isolation | Only data you explicitly add is mapped in | Each session gets its own sandbox |
| Cost to your machine | Disk, battery, performance | Not stated in source |
| Closing the laptop | Work stops | Not tied to your laptop |
/Sources
- A quote from Felix Rieseberg (Simon Willison)
- Release v2.1.291 · anthropics/claude-code
- The Sequence Radar - Issue 944: OpenAI Connects the Dots, Gemini Levels Up, and Agents Cash In
- Apple and a Hacker's Future (Stratechery)
- CVE-2026-102829 - GitHub Advisory Database
- Research: Qwen3.8 27B addition in words (Simon Willison)
- [AINews] Reflection Beam - 501B-A23B American Open Model (Latent Space)
/Key Takeaways
- The new Cowork runs both model inference and the agent's execution VM in Anthropic's cloud, with a separate sandbox for each session.
- Users rejected the old local VM over disk, battery, and performance costs, and because closing the laptop stopped the work. Privacy was not among the complaints Rieseberg cited.
- The old design already sent inference to the cloud, so local execution only ever controlled where actions ran, not where your data went.
- Cloud sandboxes replace hardware-burden problems with continuity problems, such as dropped permission answers and lost final messages, which Anthropic is already fixing in Claude Code.
- Owning the execution environment gives Anthropic the user's ongoing work, which strengthens platform lock-in and makes session-state portability the thing to watch.


