News confirmed medium confidence

GitHub Previews Copilot Computer Use for Desktop Apps

Copilot CLI and the Copilot app can operate supported desktop interfaces on macOS and Windows, with per-app approval and organization controls framing the preview.

Edited by Tyronne Panaino

GitHub put computer use into public preview on October 1 for Copilot CLI and the GitHub Copilot app on macOS and Windows. The feature lets Copilot interact with desktop applications by reading accessible interface content and visual context, clicking controls, entering or editing text, pressing keys, scrolling, dragging and moving through multi-application workflows.

The preview matters to developers and operations teams that still depend on legacy or graphical software without an API, command-line interface or MCP integration. It also expands the risk boundary: Copilot can now act through interfaces designed for people, so approval, application selection, organization policy and post-action review become central parts of the workflow.

Computer use reaches local application interfaces

The GitHub changelog describes availability in both Copilot CLI and the Copilot app. In the CLI, a user turns the capability on with the documented computer command, can inspect its status and can turn it off again. In the app, the corresponding control sits under Computer Use settings.

GitHub frames the feature around outcomes that cross application boundaries. Its examples include reading notifications in a browser, updating a presentation and moving information through a desktop workflow. That is a broader interaction surface than a tool call against a documented API because the agent may need to interpret the current visual state, locate controls and respond to interface changes.

The source does not publish a compatibility list for every desktop application, an accuracy rate for visual actions or a guarantee that a workflow will survive application updates. Public preview therefore signals that teams should test their own software, not assume every graphical process is ready for unattended automation.

Approval and managed settings define the control boundary

GitHub says Copilot asks for approval before it controls an application. Users can review or reset applications they previously chose to always allow, while organization-managed settings can disable the capability. On macOS, setup also guides users through Accessibility and Screen Recording permissions required by the operating system.

Those controls create several distinct decisions. Operating-system permission grants determine what the Copilot client can see or operate. The product approval determines whether a particular application may be controlled. Organization policy can remove access at a managed level. A durable security review should examine all three rather than treating the in-product approval as the only boundary.

An always-allow choice can reduce repeated prompts, but it also increases the importance of knowing which application state and data the agent may encounter later. Teams should begin with narrowly scoped applications, use non-production data where possible and keep a human checkpoint before consequential submissions or irreversible changes. These are practical safeguards inferred from the new control path; GitHub's announcement does not claim that the preview eliminates operational error.

The preview does not establish autonomous reliability

The official page establishes feature availability and the documented control mechanisms. It does not provide independent evidence about task success, mistaken clicks, handling of unexpected dialogs, data leakage across applications or recovery after a partial workflow. It also does not say that computer use bypasses the permissions already enforced by the operating system or the target application.

For evaluators, the useful next checkpoint is a task-level record: initial application state, requested outcome, approvals shown, actions taken, final state and any manual correction. Repeating that test across application versions would show whether the workflow is stable enough for a specific use case. Organization administrators should also verify that disabling the feature produces the intended behavior on every managed client.

Status

Confirmed. GitHub documents a public preview in Copilot CLI and the Copilot app for macOS and Windows. Internal confidence is medium because availability and controls are reported by the product owner, while reliability, security and productivity outcomes were not independently tested in this run.

Sources

Update note: Last reviewed 2026-10-03. We will revise this post if GitHub changes platform access, approval behavior, managed controls or preview status.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More News coverage