Back to Blog
Guide

Marcus Sterling7 min
F5

According to the 2025 IBM Cost of a Data Breach Report, AI-related security incidents cost enterprises an average of $4.88 million. That number has been climbing for years and nobody is happy about it. Meanwhile computer use AI agents are becoming standard in every department from sales to compliance. These agents see your screen. They click your buttons. They type your passwords. And too many organizations are running them completely exposed on production desktops. This is not a theoretical risk. Researchers found a ServiceNow Virtual Agent flaw that let attackers impersonate any user with just an email address. Another zero-click AI vulnerability enabled data exfiltration through automated prompt manipulation. These aren't edge cases. They are real attacks happening right now. You need security practices that match the power of computer use agents. Here is how to stop your AI from becoming your biggest security risk.

The Problem With Computer Use: Screenshots and Clicks Are Too Much Access

Computer use agents work by taking screenshots of your desktop, analyzing them with vision models, and then simulating mouse movement and keyboard input. This gives them near-complete control over any application you can open. That power is amazing for productivity but terrifying for security. When Claude or OpenAI's latest models do computer use, they are essentially remote desktop users with superhuman precision. They can read every document on your screen. They can navigate to settings pages. They can copy sensitive files to external locations. Most organizations still treat computer use like a chatbot on steroids when it should be treated like a privileged access management system. The security controls you use for VPN access, remote desktop, and privileged accounts do not automatically apply to AI agents. You have to build them from scratch.

3 Security Failures You're Probably Making Right Now

  • Running agents on production desktops instead of isolated environments
  • Using shared credentials that any agent can access
  • Skipping audit logging for agent actions and decisions

Claude's computer use tool lets AI control desktops with screenshot accuracy. That is exactly how attackers would exfiltrate data if they had these capabilities. The security community is warning that this is a critical vulnerability waiting to happen if you don't run it in a strict sandbox.

Zero Trust Is Not Optional for Computer Use Agents

Zero trust security assumes that every access request must be verified regardless of where it comes from. This applies to AI agents just as much as human users. You need identity-first controls specifically for agents. Every agent should have a unique identity with explicit permissions for each application and data source. Identity providers like Okta and Azure AD can manage agent identities but you must extend them beyond just human users. Map out exactly what each agent can do and limit those permissions to the bare minimum required. If an agent only needs to update a CRM, it should not have access to your file system or email. If a compliance agent only needs to read documents, it should not be able to modify or delete them. The principle of least privilege applies to AI but most organizations ignore it completely.

Sandboxing: Don't Run Agents On Your Actual Desktop

This should be obvious but it isn't. You should never run a computer use agent directly on a production machine that contains sensitive data. Instead, deploy agents in isolated environments. Cloud VMs with restricted network access. Virtual machines with read-only file systems for agents that only need to analyze data. Desktop appliances that run in a controlled sandbox. Microsoft's documentation explicitly warns that computer use carries substantial security and privacy risks. They recommend running it in environments that are separate from your main infrastructure. This is exactly what you should do. Your agents can still perform all their tasks in a sandboxed environment. They can interact with APIs, run scripts, and process data. The key difference is that if something goes wrong, you can wipe the entire instance without touching your production systems.

Audit Everything: Log Every Agent Action

When a human admin makes changes, you have logs. When a human clicks a button, you have an audit trail. When an AI agent makes changes, most organizations have nothing. You need to implement comprehensive logging for all agent activities. Record every command an agent sends to the system. Log every file it accesses or modifies. Track every API call it makes. Store these logs in a secure, tamper-proof system that can survive security incidents. AI agents are autonomous systems that can make decisions based on incomplete information. They can misinterpret tasks. They can accidentally trigger workflows they shouldn't. Without proper logging, you won't know what went wrong until after the damage is done. Audit logs should be searchable and correlated with alerts so security teams can investigate suspicious agent behavior in real time.

Why Coasty Exists (and Why It's Safer for Computer Use)

The best computer use agents on the market right now have wildly different security postures. Coasty stands apart because it is built from the ground up with security first. Our computer use agent runs in isolated environments with explicit permission controls. Every action is logged and monitored. Coasty supports BYOK so your data stays where you want it. You can deploy agents on your own infrastructure or in our cloud environment with full visibility into what they do. When you compare Coasty to other tools, look at their security architecture, not just their benchmark scores. Many competitors focus on being the smartest AI but they ignore the fact that you cannot use a smart AI if it exposes your entire organization to risk. Coasty gives you the power of computer use without the security nightmares that keep CISOs awake at night.

Computer use agents are here to stay. They will automate tasks that would take humans hours in minutes. The question is whether you will control them or whether they will control you. Organizations that treat computer use agents with the same rigor as privileged access management will get the productivity gains without the security failures. Those that treat them as glorified chatbots will eventually face breaches that cost millions. Don't wait for an incident to teach you these lessons. Start implementing zero trust, sandboxing, and comprehensive logging today. If you want to see how a secure computer use agent should work, check out coasty.ai. The future of automation is powerful but it only works if you secure it first.

© 2026 Coasty

Backed byYCombinator