In a single quarter, three of the largest companies in the industry shipped a computer use agent, and all three made the same architectural decision: give the agent a computer of its own. That choice matters more than any benchmark number, and more than the distinction this directory has been organised around since it started.
The table on the homepage sorts agents by what they control — a full desktop, or a browser tab. That column still earns its place. But it is no longer the question a reader most needs answered before deciding whether to trust one of these things, because it says nothing about the question that actually determines your exposure: whose machine is it?
Three answers, and they are not variations on a theme
Every agent in this directory resolves to one of three arrangements. They get described with the same vocabulary and they are not remotely the same product.
1. You host it
The agent is a model endpoint. You supply the desktop or the browser, you run the loop, you decide what the sandbox looks like and how tightly it is sealed. Claude Computer Use and Claude Browser Use work this way — Anthropic is explicit that nothing runs on their side — as do Computer use tool and essentially every self-hosted project here, from Browser Use to Skyvern.
This is the arrangement that gives you the most control and asks the most of you. The blast radius is whatever you decided it should be. If you put the agent in a container with no credentials and no network beyond one allowlisted host, that is genuinely where it lives. Nobody will do that work for you, and the failure mode is that nobody does it at all.
2. The vendor hosts it
The agent runs on a machine you never see. Dots is the clearest example: each one gets a cloud computer and browser of its own, deliberately kept separate from yours unless you connect them. OpenAI's cloud browser, and Perplexity Computer, sit here too.
This is the safest of the three and the least capable, and those facts are the same fact. The agent cannot touch your filesystem because it is not on your filesystem. It also cannot touch your filesystem when you want it to. What you give up is inspection: the sandbox is the vendor's design, and you cannot audit it, harden it, or verify a claim about it. You are trusting a security model you are not permitted to read.
3. It runs on the computer you are using right now
The agent is a local application with permission to drive your actual machine — the one with your actual files, your actual browser profile, and your actual logged-in sessions. Meta Muse on the Mac works this way. So do OpenClaw, Open Interpreter and Self-Operating Computer.
This is the arrangement with the best demos and the worst worst-case. Everything that makes it useful — it can see your documents, it is already signed in, it does not need you to recreate your environment somewhere else — is also the thing that makes a mistake expensive. There is no sandbox. The sandbox is your laptop.
Why this axis predicts risk and the old one does not
The desktop-versus-browser distinction implies a risk ordering: a desktop agent can reach everything, a browser agent is confined to a tab, therefore browser agents are safer. That ordering is wrong often enough to be worth retiring.
A browser agent running in a vendor's cloud with a blank profile can do very little damage, because it has nothing. A browser agent running in your browser, with your cookies, is operating every account you have ever stayed signed in to — your email, your cloud storage, your payroll system. It is confined to a tab in the same sense that a bank robber is confined to a building.
Meanwhile the thing that actually attacks these agents does not care about the distinction at all. Prompt injection works by putting instructions in content the agent reads, and what determines the damage is not whether that content arrived through a browser or a desktop application, but what the agent could reach when it believed them. The research bears this out: the defences that work operate on privilege and reachability rather than on surface (Prismata proposes least privilege for web agents).
Which gives a cleaner rule than the table currently offers. Ask what the agent can reach when it is wrong. Arrangement 2 fails safe and does less. Arrangement 1 fails however you configured it. Arrangement 3 fails with your credentials in hand.
The quarter this became the main event
None of these arrangements is new. What changed between July and October 2026 is which one the industry is betting on, and the bet is conspicuously not on arrangement 3, despite it demoing best.
OpenAI retired its consumer browser agents and rebuilt the capability around a hosted cloud browser, then went further and gave every dot a persistent machine. Meta went the other way and shipped a Mac app that acts inside native applications. Anthropic stayed exactly where it was — your infrastructure, your problem — and spent the quarter making that position easier to occupy, taking computer use out of beta, adding a browser-only toolset that addresses elements rather than pixels, and shipping SDK base classes for both (Anthropic's SDKs ship base classes for the computer and browser toolsets).
Three strategies, one quarter, and the disagreement is not about model capability. It is about who should be responsible when an agent does something irreversible. OpenAI's answer is that the vendor should hold the machine, so the vendor can contain it. Meta's is that the agent is worth having on your real computer. Anthropic's is that this is a decision the integrator has to make, because only the integrator knows what the agent is allowed to reach.
Anthropic's answer is the most honest and the least comfortable. It is also the only one of the three that admits the question exists.
What this means if you are choosing one
Start from reversibility, which is how The best computer use agent for each job sorts them, and how the pages on Invoice processing and Triaging an inbox assess individual tasks. Then apply the arrangement:
If the task is irreversible or touches money, you want arrangement 1 with a sandbox you built, or arrangement 2 with nothing connected. Not arrangement 3, no matter how much better the demo looked.
If the task needs your real files and real sessions — and plenty do, which is precisely why arrangement 3 exists — then accept that you have chosen a local agent with your credentials, and scope it accordingly. Separate user account. Separate browser profile. Not the machine your password manager is unlocked on.
If you are embedding this in a product, arrangement 1 is the only one that is actually yours. The other two are someone else's product with your name on the invoice, and when the vendor retires it — which, on this year's evidence, takes about nine months — your feature retires with it.
We are not adding a column to the directory for this yet. The vendors do not describe the arrangement consistently enough to put in a table cell without implying a precision that is not there; Meta Muse is the live example, where the reporting genuinely disagrees about whether the work happens on your Mac or in a cloud virtual machine. Until that can be sourced per entry to the standard the rest of the table is held to, it stays here, in prose, where the uncertainty can be stated out loud.