GitHub Copilot Computer Use Is in Preview
GitHub Copilot can now click, type and drag inside desktop apps. What the preview covers, the two permissions it needs, and when not to use it.
GitHub put computer use into public preview on 1 October 2026. Copilot can now operate desktop applications directly: reading on-screen content, clicking controls, typing and editing text, pressing keys, scrolling, dragging, and moving between apps. It is available in the GitHub Copilot CLI and in the Copilot desktop app on macOS and Windows.
You turn it on with /computer on, check it with /computer show, and turn it off with /computer off. In the app it also sits under Settings, Computer Use. Organisations can disable it through managed settings.
Read the sentence GitHub wrote carefully
The changelog entry says the feature expands what Copilot can automate, "including workflows in legacy and GUI-only software that do not provide an API, command-line interface, or MCP integration."
That ordering is the guidance. API first, CLI second, MCP third, and clicking around a screen last. It is a sensible ranking, because each step down that list loses something concrete:
Approach | What breaks it | How you notice |
|---|---|---|
API call | A schema change | A typed error, immediately |
CLI | A flag rename | A non-zero exit code |
MCP server | A tool signature change | A failed tool call in the transcript |
Computer use | A button moving ten pixels | Nothing, until the wrong thing is clicked |
Screen driving is the only one of the four with no contract behind it, which is the structural point in what computer use actually means. Nothing tells the agent that the dialog it is looking at is a different dialog from yesterday. That is why it belongs last, and why it is genuinely useful for the case it is aimed at: a piece of software from 2009 that has no other way in.
The permissions it needs
Copilot asks for approval before controlling an app, and you can review or reset the apps you have chosen to always allow. On macOS, the feature walks you through the two system permissions it requires: Accessibility and Screen Recording.
Those two together are a large grant. Accessibility lets a process read and drive the controls of other applications. Screen Recording lets it see what is on your display, which includes whatever else happens to be open. Granting them to a Copilot session means granting them for everything that session can be persuaded to do, not just the task you had in mind.
The practical control is the always-allow list rather than the initial prompt. One approval during a busy afternoon becomes a standing grant, so it is worth opening that list occasionally and clearing anything you no longer recognise. The same reasoning applies to restricting an agent's file system access: the grant you forget about is the one that matters.
Where this is actually worth it
Three cases justify the trade:
Software with no API at all. Desktop accounting packages, old practice-management systems, anything with a licence key and an installer and no documentation. This is the intended case.
End-to-end testing of a desktop app. Driving your own application through its real interface, in a controlled environment, where a misclick costs nothing.
A one-off migration. Pulling a few hundred records out of a system that will be retired next quarter, where building an integration would cost more than the data is worth.
What does not justify it is using screen control for something that already has an interface. If a service has a REST API, calling it is faster, cheaper, auditable, and will not break when the vendor ships a redesign. The comparison in MCP versus a REST API for agents applies here with more force, because the fallback is worse.
Before you turn it on
Run it against something you can afford to break. A preview feature that can click buttons in your email client is a different risk profile from one that can suggest code, and the review habits in reviewing an agent's plan before it runs are worth more here than in the editor, because there is no diff to inspect afterwards.
If you are comparing Copilot against other agents more broadly, GitHub Copilot versus Claude Code covers the rest of the feature surface.
Source: GitHub Changelog, 1 October 2026.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


