GitHub Copilot brings computer use to desktop applications in public preview

GitHub's October 1 preview lets Copilot CLI and the Copilot app use local desktop applications on macOS and Windows with approval and permission controls.

GitHub announced on October 1, 2026 that computer use is in public preview in GitHub Copilot CLI and the GitHub Copilot app for local sessions on macOS and Windows. Copilot can read accessible application content and visual context, click controls, enter and edit text, press keys, scroll, drag, and navigate workflows across desktop applications.

The capability targets legacy and GUI-only software that does not expose an API, command-line interface, or MCP integration. An agent can therefore try to move information between older desktop tools: read something in a browser, update a presentation, and pass the result to another local application. That expands the automation surface, but it also puts the agent in front of more unpredictable screen states and local permissions.

GitHub puts human control at the center of the feature. Copilot asks for approval before controlling an application, users can review or reset applications they have chosen to always allow, and organization-managed settings can disable computer use. On macOS, Accessibility permission is needed to interact with controls and Screen Recording permission is needed when visual context is required. These are not merely setup details; they define what the agent can see and operate.

For agent workflows, computer use changes the tool from a structured API into visual and input control. APIs usually expose explicit fields, errors, and permissions. Desktop interaction depends on window focus, changing screens, pop-ups, shortcuts, and user state. A workflow should therefore preserve an action trail, restrict allowed applications, avoid moving sensitive data into the wrong window, and retain human approval before irreversible actions rather than judging success only from the final screen.

GitHub is shipping this as a public preview, so behavior and limits may change. Good early uses are low-risk, resettable, supervised local tasks such as organizing notifications, drafting content, or operating old software in a test environment. Payments, account changes, deletion, and cross-application movement of confidential information call for stricter step-by-step approval and isolation.

The market signal is not that desktop agents can replace every GUI operation. It is that the agent's work surface is expanding from web pages and code into the computer interfaces people already use. Legacy software becomes an orchestration node, but products then need clearer permission, visibility, stop, and accountability boundaries than an ordinary chat tool.

MODULE.002 //

More insights

Ideas on websites, AI automation, digital marketing, AI news, and VMTS updates.