GitHub launched computer use in public preview Thursday, granting its Copilot CLI and desktop application the power to control programs running on macOS and Windows. Agents can now interpret application content and perform clicks, typing, scrolling, and dragging, including within older, graphical-interface-only software that lacks any API, command-line interface, or MCP integration. The company demonstrated the capability by processing an expense report in Safari, though it described additional applications including extracting summaries from legacy systems, modifying presentations, inputting data, and transferring information across programs.

Developers gain access to the feature either from the terminal or via the Copilot app, which operates on Copilot CLI and debuted earlier this year as a competitor to Claude Code and Codex. Activating computer use in Copilot CLI switches on a bundled plugin with its own MCP server, operating in local sessions by interpreting application content through the operating system's accessibility tree and capturing screenshots when visual context becomes necessary. Users enable the function with /computer on in Copilot CLI or through the Copilot app's Computer Use settings; macOS additionally requires Accessibility permission to manipulate controls and Screen Recording permission to examine windows when visual context is required. The CLI session's permission mode controls whether Copilot requests approval before accessing an application, and developers can verify it with /permissions show. Approvals stored in the CLI transfer to the desktop app on the same machine, and removing an app from the always-allowed list eliminates its approval for future sessions but preserves access already granted in a running session.

GitHub recommends using direct tools wherever available, noting that if an API, MCP server, terminal command, filesystem tool, or dedicated browser tool can accomplish the task, it generally delivers more structured information and more predictable outcomes than desktop interaction. The report notes that a shift in timing or window state can prompt Copilot to duplicate an action or freeze, and warns that the agent may select the incorrect control, type into the wrong field, or have difficulty with dynamic interfaces and complex workflows. According to the report, sensitive information visible in an application window may also become context for the agent, and unexpected on-screen content plus ambiguous instructions can trigger actions affecting the user's device, data, or connected accounts.

Enterprise policy overrides a developer's local preference, and if managed settings block computer use, Copilot CLI reports that the feature is unavailable. Through managed-settings.json, enterprise owners can also dictate whether developers may bypass approval prompts, a restriction that applies across the Copilot app, CLI, and VS Code. GitHub's default-enablement policy for Business and Enterprise does not alter this preview's opt-in status; the policy begins applying to unconfigured features on October 22 but excludes preview features. The report notes that GitHub has some catching up to do, pointing out that OpenAI added computer use to Codex in April, while Anthropic brought broader computer use on macOS to Claude Code and Claude Cowork earlier this year. The controlled rollout and reliability warnings suggest vendors are still navigating the boundary between automation convenience and unpredictable agent behavior. Organizations deploying this capability will need to weigh whether the productivity gains from automating legacy-software tasks justify the risk of unintended actions in environments where visual context can mislead an agent.