AI desk
Cursor lets cloud agents run on machines you control
Cursor's Sep 2 changelog extends self-hosted machines, which run an agent's tool calls on hardware inside your network, with support for outside sandbox hosts and computer use on Linux and Mac workers.

Cursor's Sep 2 changelog extends self-hosted machines, which run an agent's tool calls on hardware inside your network, with support for outside sandbox hosts and computer use on Linux and Mac workers.
Key points
- The feature itself is not new: Cursor made self-hosted cloud agents generally available on March 25.
- 'My Machines' ties one laptop or VM you own to your personal account; 'Team pools' are named worker queues that a whole team or company shares.
- A pool can grow as work comes in and contract when workers go offline; it can also put idle machines to sleep and wake them for a follow-up prompt inside a reconnect window.
- Pool workers can also run on sandbox hosts a team already uses: the changelog names AWS Lambda, Cloudflare, Vercel, Modal, E2B, Daytona, Coder and Namespace, and Cursor's integrations page has a team-pool setup guide for each.
- Linux and Mac workers also get computer use: once the machine is set up for it, the agent can operate mouse and keyboard, capture the screen and steer a browser. Cursor's computer-use docs say watching or taking over the agent's desktop from Cursor works on Linux only.
- Tool calls run on your own worker, which holds the repository, build cache and local credentials in place of a Cursor-hosted VM. The agent loop and model inference still run in Cursor's cloud, so what the agent reads has to travel there: Cursor's self-hosted docs name file contents, terminal output, diffs and screenshots among what a worker sends during a run.
“Your codebase, build outputs, and secrets all stay on internal machines …” — Cursor changelog
Why it matters
A one-person studio handling client sites can point Cursor's cloud agents at a spare laptop or a cheap VM, so client repositories and credentials stay on a machine you run instead of a Cursor-hosted one. It does not keep code away from the model, though, so check what the agent will read against what a privacy-minded client has agreed to. Cursor's docs also say model usage is priced the same either way, that you pay for the machines yourself and that team pools need an Enterprise plan, so a solo studio would use My Machines.
This is an AI-written summary of the reporting credited above and the other sources linked in the text, read and edited by Nicholas before publishing. The facts and any quote belong to those sources; the wording is ours. Read the original.