Cowork's architecture was publicly explained on October 5, 2026 by Anthropic engineer Felix Rieseberg: the new version runs both model inference and the virtual machine in the cloud, retiring the old design where inference was cloud-based but an Anthropic-provided VM ran on the user's own computer. Each session gets its own sandbox, sharing no state with other sessions; only when a task needs a file on the user's device does the desktop app perform that file access call.
The three complaints about the old design
The old Cowork shipped a VM to the user's machine for capability and safety reasons, mapping in only the data the user explicitly added to a session. People loved what it could do and disliked the cost: disk, battery, and performance. The most practical gripe was that closing the laptop stopped the work. For a product built to run long tasks for users, tying execution to the local machine let battery life and a lid decide how far a job could go.
After the move, the questions change
The gains are straightforward: Cowork becomes usable from a phone, work keeps running, and the local machine no longer pays the VM's battery cost. But the questions change with it. Once execution leaves the device, intermediate task state lives in cloud sandboxes, and enterprise users will ask three things: how long sandbox logs are kept, who can view them, and how state is destroyed when a session ends. Per-session sandboxes answer the isolation question, and file access still passes through the desktop app as a local checkpoint; retention and audit details, however, still need to be spelled out in the official support documentation.
What it means for teams already using Cowork
In the short term the change is about experience: long tasks no longer require sitting at the computer, and work can continue across devices. The real dividing line is compliance. Auditors used to look at a VM on an employee's laptop; now they will look at logs and policies for Anthropic's cloud sandboxes. Teams using Cowork on sensitive files should confirm two things before switching: whether sandbox data retention rules are written into their current plan's terms, and whether the records left by desktop-app file access satisfy internal audit requirements. Moving the architecture is not the risk; being unable to say where the data sits afterwards is.