Claude Cowork moves to the cloud: the sandbox left your laptop, the folder grant stayed
Anthropic's own safety page says it in one line: isolation limits where Claude's code runs, not what Claude reads or does. The cloud move relocates the first and leaves the second wired to your desktop app, which now answers for a session that keeps going after you stop watching.
Starting today, October 6, a new Claude Cowork task on a Pro or Max plan runs on Anthropic's servers, and the "Only on your computer" option in Settings > General is gone. Felix Rieseberg from Anthropic summed up the new design on the day it was announced:
The "new" version of Cowork runs model inference and the VM in the cloud.
Each session gets its own sandbox, not sharing state with other sessions.The sandbox moved and the folder grant did not. Your files are still reached through the desktop app with the permissions you set; what changed is that the session reaching them no longer stops when your computer does. My read is that where the VM runs is the small change. When the agent can be active, now that it no longer shares your computer's hours, is the large one.
What changed in Claude Cowork on October 6?
The sandbox moved. Cowork used to run Claude's code in an isolated virtual machine on your own computer; now each session gets a temporary environment on Anthropic's servers, which the safety page says "can't reach your home or company network" and is removed when the session ends.
The rest follows from that. Close the laptop and the task keeps going. Scheduled tasks run on their cadence with no device online. The October 6 notice says existing scheduled tasks move to the cloud too, including the ones that use local files, while the scheduling guide still says a task that "requires local files or apps" will "only run locally." One of those pages is out of date. Tasks you already started locally stay local until they finish, each with a button to download its transcript. On Pro and Max there is no switch back: Anthropic's answer for "this work has to stay on one machine" is Claude Code in the desktop app, and your Cowork projects and scheduled tasks do not carry over to it.
Team and Enterprise get a choice. A separate "Run Cowork in the cloud" toggle is on by default for Team and off by default for Enterprise, and with the HIPAA configuration for local mode applied, no setting turns it on.
How does a Claude Cowork cloud session reach files on your computer?
Through the Claude Desktop app, and only while it is open. A cloud session reaches the folders you connected, with the permissions you already set, and when it needs a file, "Claude fetches a copy of just that file." It is not read-only. The surface table says a cloud session "can read and write files in folders you've connected," and the safety page reminds you that Claude can also permanently delete them, after a prompt it shows in every mode.
Two sentences on the help page decide where the copy goes. The fetched copies are deleted when you delete the session, "per our data retention practices," and whether the conversation trains future models follows your setting in Settings > Privacy. Inference always ran on Anthropic's servers, so whatever part of a file Claude put into its context in the old local mode was already processed there. What is new is that the code runs there too, and a copy of the fetched file sits with a session saved to your account. Deleting a session removes it from your history at once and from Anthropic's backend storage within 30 days, per the getting-started page; the retention policy keeps data longer in a few cases: a thumbs-up or bug report you submit (5 years), a session flagged for a policy violation, or training use if you allowed it.
Does the Claude Cowork cloud sandbox protect your computer?
It protects your network from the code Claude runs. It was never meant to limit the rest, and Anthropic says so plainly on the safety page:
Isolation limits where Claude's code runs. It doesn't limit what Claude
reads or does.Count what still lands on your machine. Local MCP servers "run on your computer with the same permissions as any other program you run," which is the reach an installed tool already has. Browser use goes through a browser built into the desktop app or through your own Chrome. Computer use, per the same page, "has no sandbox between Claude and what's on your screen," gated by a permission for each app. Each local file or tool a session uses is checked against the permissions you set, and your approval mode (Manual, Auto, or Skip all approvals) decides how often Claude asks. Those are permission checks, not a sandbox. The cloud VM is sealed; the channels you hand it through the desktop app are not, which is the shape of most of the escapes OpenAI has reported, run in reverse: there the agent left through a service it had been given for another job, here the service is given on purpose and points at your machine.
Whose network does the Claude Cowork browser use?
Yours. The Team and Enterprise page states that browser traffic "comes from the user's machine," and to site operators it looks like traffic from that device "even when the session is steered from web or mobile." When the desktop app is online, the built-in browser is available from web and mobile too, so a task you start from your phone on the train browses from wherever your desktop sits, and through Claude in Chrome it uses your own Chrome with whatever that profile is signed into. That is the line that matters for agents on the web: whose session the agent is holding, not where the model happens to run.
What do the Claude Cowork docs leave open?
Three things the docs do not say. Whether connecting a folder grants every subfolder beneath it: the docs say "only the folders you've connected" and advise "a dedicated working folder for Claude rather than granting broad access," which reads like a yes but is not stated. Whether any read or write prompts per file: permissions are checked for each file, and Manual mode asks before tool actions, but the only prompt documented for every mode, Skip included, is the one before a permanent delete. And how long a fetched copy survives a session you never delete: the 30 days run from deletion, and nothing names a period for a session you keep.
The scheduling conflict above is not the only mismatch between pages. The surface table says local files work from a cloud session only if "the session was started on desktop"; the safety page lists the open app, the connected folders and your permissions, and leaves that condition out.
What should a Claude Cowork user check today?
The risk moved in time, not with the VM. A local VM stopped when the lid closed, so the agent's working hours were bounded by your computer's. A machine left awake overnight could always run unattended, but it took a decision. Now the session runs on its own clock, and every hour the desktop app stays open is an hour it can reach your folders, your local tools and your browser.
So manage two things: how long the desktop app stays open, since a closed app cuts a session off from your local files and tools (it does not stop the session, and it does not delete copies already fetched), and which approval mode you run in, since Skip means nothing checks the actions. Connect one working folder, not Documents or a home directory; anything under NDA or with credentials in it stays out of that folder. Check which scheduled tasks touch local files: they keep their cadence, and whether a run reaches your folders depends on whether the app is open at that moment. And if your computer is managed by an employer, the safety page has a line for you: connecting local folders "makes them reachable from a session in the cloud." Decide that on purpose, before the first overnight run decides it for you.