Lilith.
⌕
Editorial illustration: Claude Cowork moves its working VM off the laptop and into the cloud
Lilith illustration · editorial remix

Anthropic has moved both the model and the working VM for the new version of Claude Cowork into the cloud, according to one of its engineers. Users gain phone access, continued execution after closing a laptop and lower local overhead, in exchange for placing more trust in a remote environment.

Cowork no longer ships the working VM onto the laptop

Anthropic engineer Felix Rieseberg described the change in a quotation published by Simon Willison. The older Cowork kept model inference in the cloud but executed tool calls inside an Anthropic-provided virtual machine running on the user's computer. Only data explicitly added to the session was mapped into that VM.

The new version runs both model inference and the VM in the cloud. Every session receives its own sandbox and does not share state with other sessions. When the remote VM needs a file from the user's device, the desktop application handles that access as a separate tool call.

Rieseberg gives three practical reasons for the move: the local VM consumed disk, battery and performance, work stopped when the laptop closed and Cowork was difficult to use from a phone. The quoted description does not specify pricing or the exact rollout scope.

Convenience comes from moving the security boundary

The user benefit is immediate. A long task can continue without an open laptop, and a weaker device does not have to sustain an entire virtual machine. Cowork consequently behaves more like a cloud service for asynchronous work than a desktop application that needs constant supervision.

For security and IT teams, the more important change is where isolation happens. It moves from a local hypervisor into Anthropic's infrastructure. The desktop application remains the gatekeeper for local files, while tool execution and ongoing task state live remotely. Controls therefore need to cover per-file authorization, tool-call auditing, data retention and an immediate way to stop a session.

A separate sandbox does not complete the chain of trust

A sandbox per session limits state sharing between tasks. The short quotation does not explain retention rules, VM network permissions, access to audit records or behavior under prompt injection. Those layers will determine whether the cloud agent is suitable for sensitive documents.

The move also changes the failure mode. A local VM drained a battery and stopped when the computer closed. A cloud VM can run longer and outside the user's view, giving a poorly specified task or an overly broad permission more time and reach.

Permissions, logs and an emergency stop will decide adoption

The useful signal will be whether Anthropic gives administrators precise logs of remote tool calls, granular file and network policies and a clear retention policy. Users also need to see what the agent is doing after the laptop closes and be able to interrupt it in one step.

Team deployments will show whether session sandboxes remain genuinely isolated and whether the desktop gateway blocks files beyond the explicitly approved scope. Phone access is convenient. Enterprise adoption will depend on supervising the agent that stayed behind to work alone.

Lilith's verdict

The user closes the laptop and Cowork keeps working in someone else's data center. Anthropic now owes them a clear window and a red stop button, not merely a longer shift for the agent.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗