Detailed Analysis
A Reddit post from a Claude Pro subscriber highlights a frustrating and potentially costly bug involving Anthropic's "Cowork" feature, a computer-use capability that allows Claude to interact with a user's local machine. The user reports that despite having "Enable Computer Use" toggled off in settings, and despite never actively invoking Cowork's desktop-control functions, the system appeared to repeatedly attempt to "ping" their PC in the background during what they believed was a standard chat session. This resulted in roughly $10 in usage credits being consumed within about two minutes, on top of burning through nearly an hour's worth of standard Pro-tier usage limits during routine brainstorming and Project-setup work that should have been comparatively low-cost.
The underlying issue appears twofold. First, the user was simultaneously experiencing a separate, seemingly unrelated bug: Claude's inability to reliably write files to Google Drive, an intermittent failure spanning multiple devices and chat sessions that had already prompted a support ticket. Second, in attempting to work around that Drive problem by shifting to Claude Projects, the user triggered repeated error pop-ups indicating Cowork was trying to access their machine and failing — even though they had not knowingly enabled or used any Cowork desktop-automation functionality. This suggests either a UI/permissions bug where Cowork's background processes remain active or get triggered unexpectedly even when computer-use toggles are off, or a deeper confusion in how the product surfaces (chat vs. Projects vs. Cowork) share underlying agentic infrastructure that can silently consume metered credits.
This incident is emblematic of a broader tension in the rollout of agentic AI features. As Anthropic and competitors like OpenAI push "computer use" and autonomous coworking agents — tools capable of taking real actions on a user's machine, files, and cloud services rather than just generating text — the complexity of billing, permissions, and failure modes increases substantially. A background process that silently retries a failed action (like accessing a desktop or writing to Drive) can rack up API-style token costs invisibly, in a way traditional chat interactions never could. For users on metered plans, this transforms software bugs from mere inconveniences into direct financial harm, and it erodes trust precisely at the moment when Anthropic is trying to convince professional and enterprise users that agentic features are safe, predictable, and cost-controlled enough for real workflows.
More broadly, this case reflects growing pains familiar across the industry as chat assistants evolve into "agents" that can browse, execute code, manage files, and control desktops. Users increasingly report difficulty distinguishing when a session is "just chatting" versus when it has quietly escalated into a higher-cost, higher-risk agentic mode — a UX and transparency problem that vendors have yet to fully solve. The Google Drive integration failure compounds the issue, since cloud-storage connectors are a common integration point for these agentic features, and instability there can cascade into retry loops that are expensive for the user but invisible until the bill arrives. Anthropic will likely need to address both the specific Cowork/computer-use permission bug and the larger transparency gap — giving users clear, real-time visibility into when background agentic activity is running and the ability to hard-stop it — if it wants agentic features to be trusted rather than feared by its subscriber base.
Read original article →