GitHub Copilot Can Now Drive Desktop Apps - Off by Default, but a Saved Approval Spans CLI and App
On October 1, 2026 GitHub added computer use to Copilot CLI and the GitHub Copilot app as a public preview, on macOS and Windows. It is off until you turn it on, and choosing Always allow for an app stores that decision for both surfaces on the same machine.
On October 1, 2026, GitHub shipped computer use as a public preview, in Copilot CLI and in the GitHub Copilot app, on macOS and on Windows1.
Acting for you, Copilot can take in what an application exposes through accessibility and what is visible on screen, then click controls, type and edit text, press keys, scroll, drag, and carry a task from one application into another1. Where the content comes from is either the accessibility tree the operating system provides or a screenshot, the latter when visual context is called for2.
The case GitHub makes is about reach: software that offers no API, no command line and no MCP integration — the old in-house tool, the GUI-only package — becomes automatable because the screen is treated as the interface1.
GitHub says to use something else if you can
The documentation draws a line. When an API, an MCP server, a terminal command, a filesystem tool or a purpose-built browser tool can finish the job directly, GitHub’s position is that those routes generally hand back better-structured information and behave more predictably2. Computer use is the option for work that genuinely requires a visual interface.
Tool choice is made by the agent as it goes, and the session record lets you see what it reached for2. Handing an AI agent that much latitude now extends to the screen itself.
Off by default, and whether it asks depends on the surface
Computer use starts disabled; nothing happens until you switch it on2. How you do that differs by surface. In Copilot CLI it is /computer on to enable, /computer show to read the current state, and /computer off to turn it back off. In the Copilot app it is Settings, then Computer Use, then Enable Computer Use — or the same /computer on1.
Whether you get asked is not fixed either. Per the documentation, computer use inherits the tool permission settings of whichever Copilot surface the session belongs to, and it is those settings that decide if approval is requested before an application is driven; they can be configured per surface2. When a prompt does appear, the three answers available are to allow for this session, to keep the approval for later sessions, or to refuse.
Worth separating out: Copilot’s default policy for new features, which takes effect on October 22, does not reach features still in preview. Computer use, sitting in public preview, is not among the things that policy will switch on.
A saved approval spans CLI and app
This is the part that shapes how you set it up. Pick Always allow for a particular application and the decision is kept locally, and it then applies to Copilot CLI as well as the GitHub Copilot app on that same machine2. An approval granted once from the terminal is live for app sessions too.
Revocation has the same reach, with one asymmetry. Open the list of always-allowed applications in the app and delete an entry, and the stored approval is gone from future sessions on both sides — but access a running session already holds is not withdrawn2. Stopping an agent mid-flight is a matter of stopping the run, not of editing settings. Interrupting means Esc twice in Copilot CLI, or the Stop control or Esc in the Copilot app.
Precedence is spelled out as well. A permission rule that denies a tool beats both automatic and stored approvals2. On the administrative side, enterprise administrators can switch computer use off through managed settings, and turning it on locally does not get around an enterprise policy. The changelog likewise notes that managed settings can disable the feature1. Either way, what the user enables does not outrank what the administrator decided.
On macOS you are handing over two system permissions
macOS users get walked through granting two things: Accessibility, so controls can be operated, and Screen Recording, so windows can be inspected when visual context is needed2.
Granting screen recording means whatever is on display at that moment can become input. The documentation works from that premise, warning that application windows may show sensitive material, including material about other people, and asking you to limit the feature to applications, and to work, where you are content for everything on display to be handed to Copilot as context.
The risk section is unusually concrete
A warning block in the documentation states that vague instructions, or something unexpected appearing on screen, can lead to actions you did not intend — reaching your device, your data, or accounts you are connected to, among them personal, financial and enterprise systems. It adds that computer use does not replace human judgement, and asks for a look at the target application, the permissions requested and the outcome, especially ahead of anything that alters data or lands on other people2.
The technical limits are listed too. An interface is not stable across releases of an application, across operating systems, or across the states a window can be in, so the wrong control can be picked, text can land in the wrong field, and controls that are dynamic or depart from the standard, along with workflows of many steps, can give it trouble. A change of timing, or of what state the window is in, can alter the result, make an action repeat, or stop progress altogether.
Always allow carries its own note: once chosen, subsequent computer-use actions reach that application without asking again, so GitHub advises against choosing it for applications holding sensitive material or capable of high-impact operations.
More to settle before switching it on
The previous day’s changelog carried HydraFusion in VS Code, but that one is about how models get used, while this is about what gets touched on your own machine. It is in public preview, with the spec still liable to move.
Three things are worth deciding before you try it. Which applications, if any, get Always allow — remembering the decision carries across CLI and app. Whether the organisation turns this off through managed settings or leaves it to individuals. And, on macOS, whether this is a machine you are willing to grant Screen Recording on. The opening it creates for automating GUI-bound business systems is real; so is the fact that the route in is one where everything on screen goes to the model.
Sources
- GitHub Copilot can now interact with desktop apps with computer use - GitHub official changelog (October 1, 2026)
- About computer use in GitHub Copilot - GitHub Docs (accessed October 2, 2026)
Was this article helpful?
Thank you!
Received. Thank you!