- The gist: Anthropic launched Cowork on Monday, bringing AI agent file-manipulation capabilities to mainstream users through Claude Max subscriptions ($100-200/month), while simultaneously warning users the tool could delete files and expose data to prompt injection attacks.
- Key details: The team built Cowork in 10 days with Claude Code writing all the code. Available as macOS-only research preview, it lets non-technical users designate folders where AI can read, modify, or create files using Apple’s VZVirtualMachine sandbox.
- Why it matters: This marks a shift from developer-focused AI tools to mainstream file-access agents, but security researchers warn the launch is premature. OWASP ranks prompt injection as the #1 LLM security threat, and Anthropic admits agent safety remains “an active area of development.”
- Context: Anthropic built Cowork after observing Claude Code users repurposing the developer tool for vacation research, email cleanup, and photo recovery. Microsoft Copilot already dominates enterprise with 90%+ Fortune 500 penetration, leaving Anthropic competing from a consumer-first position.
Just days after gaining access to Cowork, tech expert Lenny Rachitsky fed 320 podcast transcripts into Anthropic’s new AI agent. Minutes later, he had extracted themes and insights that would have taken a human analyst days to compile.
His experiment captures both the promise and peril of Monday’s launch: Anthropic released a powerful file-manipulation tool for mainstream users, including people who may not recognize the security risks embedded in that power.
Cowork brings AI agent capabilities to Claude Max subscribers at $100 to $200 per month on macOS. The tool extends Claude Code’s file manipulation capabilities beyond developers, letting non-technical users designate folders where the AI can read, modify, or create files.
Yet Anthropic simultaneously warned those same users the tool could delete their files and expose sensitive data to prompt injection attacks, problems the company admits remain unsolved.
Making Claude Code Accessible
The new tool builds on Claude Code’s underlying architecture while removing technical barriers. Anthropic first unveiled Claude Code in February 2025 as a terminal-based tool for software engineers. Cowork strips away the command-line interface and ships with a folder-based sandbox configured automatically through Apple’s VZVirtualMachine framework.
The product integrates with Anthropic’s ecosystem of connectors including Asana, Notion, and PayPal. Anthropic described the positioning in its announcement: the tool lets users “complete non-technical tasks much like how developers use Claude Code.”
This integration means Anthropic now competes not just with conversational AI assistants but with productivity agents like Microsoft Copilot in enterprise and consumer markets.
From Coding Tool to General Agent
The product emerged from an unexpected pattern Anthropic observed among Claude Code users. Users deployed the developer tool for vacation research, building slide decks, cleaning up email, cancelling subscriptions, recovering wedding photos from hard drives, monitoring plant growth, and controlling ovens.
Boris Cherny, an engineer at Anthropic, noted the diversity: people were using the coding tool “for all sorts of non-coding work.”
The creative misuse extended beyond casual experiments. Rachitsky’s transcript analysis demonstrates the tool’s viability for content work at scale. These use cases share a common pattern: users with messy piles of unstructured data (receipts, transcripts, photos) seeking structured outputs (spreadsheets, summaries, organized folders) without writing code.
This pattern reveals a latent demand for AI-powered file organization that developers glimpsed first but that extends far beyond technical users.
Introducing Cowork: Claude Code for the rest of your work.
Cowork lets you complete non-technical tasks much like how developers use Claude Code. pic.twitter.com/EqckycvFH3
— Claude (@claudeai) January 12, 2026
Recursive Development at Breakneck Speed
That creative deployment led to an unconventional development approach. The team built the entire Cowork feature in ten days, with Cherny confirming that “all of the product’s code was written by Claude Code.”
This recursive improvement loop (AI agents building their own successors) suggests development velocity may soon exceed human capacity to audit security implications. Traditional software development cycles measured in months collapse to days when the development tool becomes the developer.
If Cowork can build its own successor in ten days, security researchers face an impossible race. This demonstrates why Anthropic ships features faster than it can secure them.
Security Warnings Cloud Launch
That speed comes with trade-offs security researchers warn may be premature. Anthropic explicitly acknowledges the risks inherent in giving mainstream users file system access. The company’s announcement warns that “Claude can take potentially destructive actions (such as deleting local files) if it’s instructed to.”
The warning carries particular weight given prompt injection risks: attackers can embed hidden commands in documents or webpages that hijack AI behavior.
A malicious PDF could instruct the AI to delete files, exfiltrate data, or modify documents without user knowledge. The Open Web Application Security Project (OWASP) ranks prompt injection as the #1 security threat to large language model applications.
AI systems cannot reliably distinguish legitimate instructions from malicious ones embedded in content they process.
Anthropic’s own messaging reveals the incomplete state of defenses. The company stated it has “built sophisticated defenses against prompt injections” but acknowledged that “agent safety is still an active area of development in the industry.”
That phrase signals ongoing research rather than deployed solutions.
Simon Willison, a prominent AI blogger, criticized the responsibility shift: asking regular users to watch for “suspicious actions that may indicate prompt injection” places detection burden on those poorly equipped to handle it.
Anthropic asks users to spot attacks that security professionals struggle to detect.
Security firm Lakera frames the challenge more fundamentally, calling indirect prompt injection “a structural weakness in how AI systems process context,” not a bug to be patched.
These critiques expose a troubling mismatch: Anthropic ships a consumer-facing tool while acknowledging the underlying safety problem remains unsolved. The tension between shipping fast and shipping safely has resolved in favor of velocity. For users, this means their files are only as safe as Anthropic’s still-incomplete defenses.
Sandboxing Approach
Anthropic’s answer to these concerns relies on Apple’s virtualization technology. The system uses Apple’s VZVirtualMachine (part of the Apple Virtualization Framework) to confine Claude’s file access to user-designated folders. This provides process-level isolation between the AI agent and the host operating system.
The sandbox approach mitigates some risks but doesn’t address prompt injection vectors. A malicious instruction in a document can still cause file deletion or data exfiltration within the allowed folder scope.
Anthropic previously implemented similar sandboxing for Claude Code for web, suggesting an iterative approach to agent safety. Anthropic is learning as it ships rather than waiting for complete solutions.
Competing Against Microsoft’s Enterprise Dominance
While Anthropic refines its sandbox, the broader agent market is heating up. Microsoft’s Copilot has captured over 90% of Fortune 500 companies, according to the company’s Ignite 2025 announcement. Microsoft’s enterprise dominance leaves Anthropic competing from a consumer-first position.
Cowork’s research preview status and premium pricing ($100-200/month for Claude Max) suggest a cautious scaling strategy rather than direct enterprise challenge.
The macOS-only limitation further restricts the addressable market during this initial phase. Where Microsoft pursues enterprise deployment at scale, Anthropic appears to be testing consumer appetite for file-manipulating AI agents while monitoring for safety issues.
Platform Limitations Signal Cautious Rollout
The tool remains exclusive to macOS, with Windows support planned but not scheduled. The macOS-only limitation has drawn criticism from reviewers expecting cross-platform availability in 2026. The research preview designation and Claude Max subscriber requirement create further barriers to mass adoption.
These limitations may be strategic rather than technical. By gating access behind premium subscriptions and limiting to a single platform, Anthropic controls the rate of adoption and the volume of edge cases the system must handle. This suggests Anthropic recognizes the security challenges inherent in mainstream file access, even if it cannot yet solve them.
What Comes Next
Users like Rachitsky will determine whether Cowork fulfills its promise or triggers the security incidents critics fear. Each transcript analyzed, each folder organized, each file modified adds data points to Anthropic’s understanding of how mainstream users interact with file-manipulating AI.
The company has set a research preview window without announcing when broader access will follow or what safety milestones must be met first.
For the thousands of Claude Max subscribers now weighing whether to grant Cowork access to their files, the calculation is concrete. Anthropic plans to monitor the research preview closely and expects to expand access if early results prove safe.
But users who lose files to a prompt injection attack in the meantime will find little comfort in knowing they were early adopters of a tool Anthropic itself warned was not fully secured.


