AI agents are touching your keyboard now. What could go wrong?

AI agents are touching your keyboard now. What could go wrong?

This week, Anthropic shipped "computer use" for Claude, a feature that lets the AI open apps, browse the web, fill spreadsheets, and submit pull requests on your Mac. You message Claude from your phone, and it does the work on your computer while you're away. The feature launched in research preview for Pro and Max subscribers and pairs with Dispatch, a mobile tool that lets you assign tasks remotely.

This is part of a wider sprint. OpenClaw, the open-source agent framework, went viral earlier this year and drew enough attention that its creator got hired away. Multiple labs are now racing to ship agents that go beyond chatting and start doing. As one CEO put it last week, these agents are "the next ChatGPT."

So here's the thing: we're watching a category shift in real time, and most development teams aren't thinking about it from the right angle.

The real problem isn't the AI. It's the access.

When we run penetration testing engagements for gaming studios and enterprise clients, the scariest findings are rarely exotic exploits. They're permission problems. Service accounts with too much access. Admin tools left wide open. Credentials stored where they shouldn't be.

Now picture giving an AI agent the ability to click, type, and browse your desktop. Anthropic says Claude will ask permission before accessing new apps, and users can stop it at any time. That's a reasonable starting point. But "reasonable starting point" and "production-ready for teams handling sensitive data" are very different things.

Claude's computer use currently works only on macOS. It's screenshot-driven, meaning it reads pixels on your screen to figure out what to do next. If a password manager auto-fills while Claude is watching, it sees that. If a Slack thread with customer PII scrolls past, it sees that too. Anthropic themselves said the feature "is still early compared to Claude's ability to code or interact with text" and warned that "Claude can make mistakes."

That honesty is appreciated. But I think teams are going to adopt this faster than they build guardrails around it.

What this means for developers

The developer-facing side is interesting. Anthropic says Claude can make changes in an IDE, submit pull requests, and run tests. If you're a solo developer shipping a side project, that could genuinely save time.

For teams, though? We build web applications and APIs for enterprise clients with compliance requirements, often in regulated industries across Europe. The idea of an AI agent autonomously submitting PRs and running tests raises questions that go beyond "is the code correct." Who reviewed it? What data did the agent access to write it? Is there an audit trail?

A recent study of 700 engineers found that 69% of developers who use AI coding tools very frequently experience deployment problems "always, nearly always, or frequently" when AI-generated code is involved. The code is getting written faster, but the testing, security, and deployment infrastructure hasn't caught up. Adding an agent that can also push buttons in your IDE doesn't fix that gap. It widens it.

From our PHP and Docker work on cloud-native applications, we've learned the hard way that speed without guardrails just means you break things sooner. The teams that ship reliably aren't the ones writing code fastest. They're the ones whose CI/CD pipelines, code review processes, and security checks are solid enough to absorb velocity.

Mobile teams should be paying attention too

This might seem like a desktop story, but it's not. The Dispatch feature specifically bridges phone and computer. You fire off a task from your iPhone and Claude executes it on your Mac. That's a cross-device workflow pattern we're going to see a lot more of.

In our native iOS and Android projects, especially in healthcare and IoT, we've dealt with the headaches of coordinating actions across devices for years. The hard part was never the communication layer. It was trust boundaries. Which device is authoritative? What happens when the remote action fails silently? How do you surface errors to users who aren't watching the screen where the action happened?

Agent-driven workflows between phone and desktop will hit exactly the same problems, except now the "user" in the loop is an AI that can't tell you it's confused. It just keeps clicking.

What to do right now

Here are things your team can do this week, before anyone installs a computer-use agent on a work machine:

  1. Audit what's on screen. If your developers have customer data, credentials, or internal dashboards visible on their desktops, an agent that can take screenshots can see all of it. This is the same attack surface we test during security reviews, just triggered by a tool you invited in.

  2. Set a policy before the tool arrives. Decide now whether agents that can control computers are approved for your org, for which use cases, and on which machines. Retrofitting policy after adoption is painful.

  3. Don't skip the boring stuff. If your CI/CD pipeline, test coverage, and code review process aren't solid enough to catch bad human code, they definitely won't catch bad AI-generated code pushed by an autonomous agent. Shore up your development workflow first.

  4. Watch the permissions, not the demos. The flashy demos show Claude exporting a PDF. The risk is in what else it can reach while doing so. Treat agent access the way you'd treat a new contractor's first day: least privilege, scoped access, supervised until trust is earned.

The bigger picture

I keep coming back to a pattern we see across our work with enterprise clients: new capabilities get adopted faster than the security and process maturity needed to support them. It happened with cloud migration, it happened with containerization, and it's happening with AI agents now.

The technology is genuinely impressive. Watching an AI browse your desktop to complete a task is a real "oh, we're here now" moment. But impressive and production-ready are not the same thing, and I'd rather our clients be six months behind the hype curve with their data intact than on the bleeding edge with an incident report.

Anthropic, to their credit, isn't overselling this. They called it a research preview, flagged the limitations, and said threats are constantly evolving. That's the right posture. I just wish every team evaluating these tools would approach them with the same caution.

If figuring out where AI agents fit (or don't fit) in your development workflow sounds familiar, let's talk.

ai-agentsexpert-analysissecuritysoftware-developmenttech-news