- On October 1, 2026, GitHub launched computer use in public preview: Copilot CLI and the Copilot desktop app can now click, type and scroll inside other desktop apps on macOS and Windows.
- It is off by default, asks before controlling each app, and enterprises can disable it. GitHub hasn't said which plans get it or what it costs in AI credits.
- GitHub shipped dynamic workflows the same day and made local sandboxing generally available on October 7.
Contents
On October 1, 2026, GitHub put computer use into public preview for GitHub Copilot. Copilot can now operate ordinary desktop applications, reading what's on screen and clicking, typing, scrolling and dragging, from two places: the Copilot CLI and the GitHub Copilot desktop app. It works on macOS and Windows. It widens what Copilot's agent can reach well beyond the code editor and terminal. It also brings a familiar set of risks, and GitHub's own documentation spells them out.
What shipped
According to GitHub's changelog and documentation, computer use lets Copilot:
- read app content through the operating system's accessibility tree, or take screenshots "when visual context is needed";
- click controls, enter and edit text, press keys, scroll and drag;
- move through multi-step workflows across several apps.
GitHub aims it at software that has no API, command-line interface or MCP server, such as legacy line-of-business tools and GUI-only apps. Its launch examples included filling in an expense report and updating a presentation.
GitHub also recommends against reaching for computer use first. Its docs and the launch coverage both say direct tools (APIs, MCP servers, terminal commands, file and browser tools) give more structured, predictable results when they can do the job. Computer use is the fallback for when nothing else can.
It is local only. It runs in sessions on your own machine, not in Copilot's cloud agent, and the docs don't mention VS Code. The Copilot app also runs on Linux, but computer use is listed for macOS and Windows only.
How to turn it on
Computer use is disabled by default.
- Copilot CLI: run
/computer on./computer showreports the status and/computer offturns it off. - GitHub Copilot app: open Settings › Computer Use and switch on Enable Computer Use. You can also type
/computer on. - macOS: setup walks you through granting Accessibility and Screen Recording permissions.
- To stop it mid-action: press Esc twice in the CLI, or click Stop (or press Esc) in the app.
Before Copilot controls an app, it asks. You can allow access for the current session, save the approval with "Always allow", or deny it. Saved approvals are stored locally and apply to both the CLI and the app on that computer. Deny rules override any automatic or saved approval.
For organizations, GitHub says enterprise administrators can disable computer use through managed settings, and that "enabling computer use locally does not override an enterprise policy." GitHub has also introduced a new default-enablement policy for Business and Enterprise accounts, which takes effect on October 22, 2026. It covers only generally available features, so preview features like computer use stay opt-in.
Who can use it, and what it costs
GitHub hasn't said which Copilot plans include computer use. The changelog and docs only describe it as a public preview "subject to change." That was still the case when we re-checked both pages on October 9, 2026. The two surfaces it runs on, the Copilot app and Copilot CLI, are included in every Copilot plan, according to GitHub's plans documentation. Until GitHub confirms otherwise, treat plan coverage as unspecified.
On cost, one correction to a common assumption: Copilot no longer bills by "premium requests." Since June 1, 2026, every Copilot plan has billed in GitHub AI Credits, where one credit equals $0.01. Usage is token-based: "Each token is priced based on the model used." GitHub lists Copilot CLI and the cloud agent among the features that consume credits. Code completions and next edit suggestions don't.
GitHub hasn't published a separate rate for computer use. Screenshots add input tokens, so sessions that rely on them are likely to use credits faster than text-only agent work, but GitHub hasn't put a figure on it.
Last verified: October 9, 2026 (GitHub Docs, "Plans for GitHub Copilot")
| Plan | Price | Included AI credits per month |
|---|---|---|
| Copilot Free | $0 | Limited allowance (amount not published) |
| Copilot Pro | $10/month | 1,500 (1,000 base + 500 flex) |
| Copilot Pro+ | $39/month | 7,000 (3,900 base + 3,100 flex) |
| Copilot Max | $100/month | 20,000 (10,000 base + 10,000 flex) |
| Copilot Business | $19/seat/month | 1,900 per user, pooled |
| Copilot Enterprise | $39/seat/month | 3,900 per user, pooled |
Business and Enterprise usage beyond the pool is billed at $0.01 per credit. Individual subscribers who run out can upgrade, set a budget for additional usage, or wait for the monthly reset.
The risks GitHub lists
GitHub's computer use documentation is blunt. It warns that the agent can misread interfaces that change between app versions, OS builds or window states, and that it "can select the wrong control, enter text in the wrong location". It also says unexpected on-screen content or ambiguous instructions "may cause unintended actions that affect your device, data, or connected accounts."
Two practical consequences follow. First, anything visible in a window Copilot controls can end up in the model's context, so GitHub advises using the feature only with apps whose visible content you're comfortable sharing. Second, GitHub recommends against "Always allow" for sensitive or high-impact apps. Our case against unattended agents explains why a stray instruction on a web page or in a document is a real attack path, not a theoretical one.
The same week: dynamic workflows, HydraFusion and sandboxing
Computer use was one of several Copilot agent changes in a short window:
- Dynamic workflows (October 1, public preview): multi-step processes defined in code that mix automated steps with one or more agents, run in sequence or in parallel, and can pause at checkpoints for your input. They're available in Copilot CLI, the Copilot app and the Copilot SDK, and GitHub says they're "available on all Copilot plans." In the CLI you need the latest version and experimental features turned on (
--experimentalor/experimental on). - HydraFusion (September 30, research preview): appears in the model picker but coordinates several models in one turn. It can use a single model, a cheap draft escalated to a stronger model, or a draft reviewed by a critic from a different model family. It's now in VS Code 1.140+ and the Copilot app for Pro, Pro+, Business and Enterprise.
- Local sandboxing (generally available October 7): restricts what Copilot-initiated tools and commands can do with your files, network and credentials. It works in Copilot CLI, the Copilot app and VS Code sessions using Agent Host. It's powered by Microsoft eXecution Container (MXC), and enterprises can enforce policies developers can't weaken. GitHub says it's included at no extra cost.
GitHub's docs don't say whether the local sandbox also constrains computer use's clicks and keystrokes, which act through the OS accessibility layer rather than shell commands. That is worth confirming before you combine the two on a work machine.
Why it matters
Computer use moves Copilot further from code completion and closer to the general-purpose desktop agents its rivals already offer. The New Stack, which covered the launch on October 2, notes that OpenAI added computer use to Codex in April and that Anthropic brought broader macOS computer use to Claude Code earlier this year. It concluded that GitHub "has some catching up to do." For how Copilot's agent stacks up against Claude Code, Codex and Cursor, and what separates an agent from an assistant, see our explainer on what "agentic" really means.
What's confirmed and what isn't
- Confirmed (GitHub): launch date, public-preview status, CLI and app surfaces, macOS and Windows support, off-by-default behavior, the approval model, enterprise disable switch, and the AI Credits billing model.
- Not stated: which plans include computer use, its credit cost, and whether local sandboxing applies to GUI actions.
- Reported (third party): competitor timelines, per The New Stack.
What to do next
If you manage Copilot for an organization, decide on a computer use policy now and review the default-enablement setting before October 22. If you're an individual developer, try it first on a low-stakes app and avoid "Always allow." For the competitive picture, see Cursor's latest release, which also offers computer use on self-hosted workers, and The Week in AI #2 for the rest of that week's agent news.
About this storyBased on the sources linked below. Editorial standards




