Anthropic Hides Claude in the Background — and IT Departments Are Terrified
Claude now uses a strict three-tier delegation system to operate desktop apps in hidden windows. But the cost of an autonomous coworker is unmonitored access.

As of September 2, Anthropic’s Claude can operate desktop apps in invisible background windows. You can be typing an email in the foreground while the AI is silently clicking, navigating, and scraping data in a hidden instance of Chrome right behind it. If you happen to be mid-keystroke, it pauses its invisible work to avoid interfering.
The End of the Hostile Takeover
Until now, handing a task to an AI agent meant surrendering your hardware. When older models took control of a cursor, they treated computer use as a brute-force visual takeover of the primary screen. If the AI was working, you could not be.
Anthropic just broke that constraint. By pushing Claude Cowork and Claude Code into the background on macOS 15, the company has functionally turned a single Mac into a two-person workstation.
To guarantee speed and prevent rogue inputs, Claude operates on a strict fallback system. It first tries native connectors like Gmail or Slack APIs. If those fail, it moves to the built-in browser. Only as an absolute last resort does it fall back to directly navigating your desktop interface. It acts less like a software script and more like an intelligent employee who only resorts to manual data entry when the automation breaks down. But creating this kind of autonomy requires a fundamental shift in how we talk to machines.
Building the Invisible Doer

The architects behind this shift want to kill the chat interface. Boris, the creator of Claude Code, designed the system to move users away from back-and-forth prompting toward true parallelism.
“I think about productivity as parallelism: multiple tasks running while I steer outcomes. I use Cowork as a 'doer,' not a chat.”— Boris, creator of Claude Code
This unlocks a totally new user behavior. Content creators who stress-tested Claude's full stack found a massive divide between casual users typing into a browser and power users treating the AI as a small remote team. You can assign Claude a messy job—like finding UX issues in a phone simulator or pulling a competitive analysis from local files—and completely ignore it.
By restricting this initial rollout to macOS, Anthropic has also fired a quiet shot in the operating system wars. Apple is suddenly positioned miles ahead of Windows for local, autonomous AI. But turning an operating system into a shared workspace introduces a terrifying reality for the people tasked with securing it.
What people are saying
“Claude can now use your computer in the background in Claude Cowork and Claude Code. Give it something to do on your desktop and Claude clicks, types, and opens apps just like you would, while you work on something else.”

“Anthropic has confirmed Claude Fable 5.1 has undetectable watermarks to anyone who does not have their detection API.”

“Anthropic paused parts of its own training after Claude models did things they weren't supposed to, put 150 engineers on security, and wrote it all up publicly. You can read that as trouble. I read it as a lab actually acting on its own warning signs, which is rarer than it”
Ending the AI Hostile Takeover
The Brief
Stay curious
AI and technology: what changes and why it matters.
Your daily selection, in English or Spanish.
Free forever. Unsubscribe anytime.
More stories

The Specialty News





Conversation
Start the conversation