ReviewUpdated 2026-09-12

Cua Review 2026: Computer-Use Agents, Pricing, and Security

A research-based Cua review covering capabilities, pricing, privacy, limitations, alternatives, and a practical buyer test.

By DiscoverAI Editorial TeamReviewed by DiscoverAI Editorial Review2 min readBuild, Design & GovernHow we evaluate
Paper-cut AI operator coordinating isolated Linux Windows macOS and Android workstations through permission gates
Original DiscoverAI editorial illustration. Computer-use infrastructure needs disposable environments, deny-by-default permissions, verified state, and approval before consequential actions.

Bottom line

Cua is open-core infrastructure for giving AI agents isolated computers, GUI control, cross-OS fleets, and evaluation environments through SDK, CLI, and MCP interfaces.

Editorial accountability

Who checked this guide

Meet the editorial team →
Evaluation type
Hands-on evaluation
Last materially checked
Evidence
4 listed sources

Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.

Editorial freshness

Checked this month

Pricing and material product claims were checked September 12, 2026.

Review evidence

What this guidance is based on

Review type
Research-based product assessment
Material review date
September 12, 2026
Evidence
Current first-party product, pricing, documentation, privacy, and security material
Buyer test
Controlled quality, cost, permissions, privacy, reliability, and failure-path evaluation

Important limits

  • DiscoverAI did not complete the proposed long-term paid deployment for this review.
  • Features, prices, limits, security controls, and provider data paths can change; verify the linked first-party pages before purchase.
In this guide
  1. Short answer
  2. Best for
  3. Look elsewhere if
  4. What Cua verifiably does
  5. Important limitations
  6. Cua pricing
  7. A fair buyer test
  8. Final verdict

Short answer

Cua is worth testing when an agent must operate native desktop applications or move across code, APIs, and graphical interfaces—not merely browse a website. Cross-OS support and local deployment are compelling, but computer control is privileged and nondeterministic. Buyers need deny-by-default tool policies, disposable environments, evidence for every action, and human approval before consequential writes.

Best for

  • Computer-use agents spanning native and web applications
  • Cross-OS agent training and evaluation
  • Teams needing local, cloud, BYOC, or on-premises options

Look elsewhere if

  • Simple workflows with dependable APIs
  • Production desktops containing broad user credentials
  • Autonomous consequential actions without approval

What Cua verifiably does

Cua documents sandbox runtimes across Docker, QEMU, Apple Virtualization, and cloud machines; a Driver for background GUI input and observation; fleets for concurrent rollouts; and Cua Bench for agent evaluation. Its interfaces support MCP, CLI, Python, and multiple model or agent harnesses. Current materials describe Linux, Windows, macOS, and Android environments, with BYOC and on-premises paths.

Important limitations

A capable model can still click the wrong target, misread state, leak information through an application, or repeat an irreversible action. Cua Driver's policy engine is restrictive only when a policy is configured; the documentation says an absent policy allows calls. Local operation shifts host permissions, VM isolation, patching, secrets, retention, and incident response to the buyer.

Cua pricing

Cua's open-source Sandbox, Driver, Bench, and Lume components can run locally without a software subscription. Cua Fleet lists $0.044625 per vCPU-hour and $0.0223125 per GB-hour; model inference, storage, operating-system licensing, network traffic, and engineering remain separate. BYOC and on-premises arrangements are available. Reviewed September 12, 2026.

A fair buyer test

Run 250 tasks across two operating systems and five applications, including stale windows, ambiguous controls, hidden dialogs, denied permissions, prompt injection, network failure, duplicate submissions, and destructive actions. Measure verified completion, silent error, intervention, duplicate effects, policy bypass, recovery time, retained artifacts, and fully loaded cost per accepted task.

Final verdict

Cua earns a pilot for engineering teams whose agents genuinely need native-computer access or cross-OS evaluation. Start with disposable, non-production machines and read-only tasks. Require an explicit permission policy, isolate identities and credentials, and promote write access only after failure-path results are acceptable.

This is a research-based product assessment, not a claim of hands-on long-term testing. Product, pricing, privacy, security, and usage claims were checked against the first-party sources below on September 12, 2026. Verify current terms and run the proposed test with approved data before adoption.

Reusable trial worksheet

Test Cua before you commit

Turn this review’s buyer test into evidence. Your entries autosave only in this browser and are never added to shared shortlist links.

0/7 checks complete
  1. Confirm the tool meets every must-have workflow and stakeholder requirement.

    Review starting point: Computer-use agents spanning native and web applications; Cross-OS agent training and evaluation; Teams needing local, cloud, BYOC, or on-premises options

  2. Run the same representative work you would use in production; do not score a polished demo.

    Review starting point: Run 250 tasks across two operating systems and five applications, including stale windows, ambiguous controls, hidden dialogs, denied permissions, prompt injection, network failure, duplicate submissions, and destructive actions. Measure verified completion, silent error, intervention, duplicate effects, policy bypass, recovery time, retained artifacts, and fully loaded cost per accepted task.

  3. Calculate the effective cost per accepted result, including usage, review, corrections, and required add-ons.

    Review starting point: Cua's open-source Sandbox, Driver, Bench, and Lume components can run locally without a software subscription. Cua Fleet lists $0.044625 per vCPU-hour and $0.0223125 per GB-hour; model inference, storage, operating-system licensing, network traffic, and engineering remain separate. BYOC and on-premises arrangements are available. Reviewed September 12, 2026.

  4. Define an acceptance threshold, test known answers and edge cases, and record every correction.

    Review starting point: Editorial quality signals: features 4.3/5; AI quality 4.0/5. Validate these signals in your own work.

  5. Verify what data enters the product, who can access it, how long it is retained, and whether it trains models.

    Review starting point: Use approved low-risk data first. Check roles, consent, deletion, subprocessors, model-training settings, and the contract—not only the marketing page.

  6. Test the real handoffs, permissions, failure states, and export path your team depends on.

    Review starting point: OpenAI Codex, Claude Code, Gemini, MCP, Python, Terraform

  7. Record training, governance, reliability, accessibility, ownership, and change-management risks before rollout.

    Review starting point: GUI automation remains nondeterministic; Safe defaults depend on configuration; Total cost extends beyond compute rates

Open Decision Workspace

Loading saved worksheet… · private to this device or your optional account

Community evidence

How verified users put Cua to work

Structured, editor-moderated experience—not star ratings. This complements our independent review and never changes its score.

No approved community evidence yet. Be the first verified user to contribute.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

What is Cua?

Cua is infrastructure that gives AI agents isolated computers and a driver for operating code, tools, APIs, and graphical interfaces.

Is Cua free?

Its core local components are open source; managed Cua Fleet usage is billed by CPU and memory, with other workload costs separate.

Which operating systems does Cua support?

Cua advertises Linux, Windows, macOS, and Android environments, with exact features varying by runtime and deployment.

Does Cua make computer-use agents safe?

No. It supplies isolation and policy controls, but buyers must configure permissions, constrain credentials, verify actions, and require approval for consequential steps.

Found this useful?

Get the next one in your inbox.

One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.

Free · one email a week · unsubscribe any time

Recommended tool

Use Cua if this workflow fits your team

Open-core cross-OS computer runtime

Tools mentioned in this article

Cua

Run computer-use agents across Linux, Windows, macOS, and Android

4.1

Cua is open-core infrastructure for giving AI agents isolated computers, GUI control, cross-OS fleets, and evaluation environments through SDK, CLI, and MCP interfaces.

FreemiumAutomationCode

Browser Use

Open-source and cloud infrastructure for AI agents that navigate websites

4.0

Browser Use helps developers run web agents, remote browsers, profiles, proxies, and reusable skills, but reliability, credential custody, website rules, variable usage costs, and human approval are decisive.

FreemiumAutomationCode

Steel

Run browser agents with managed sessions, proxies, profiles, credentials, replays, and observability

4.1

Steel is an open-source browser API and managed cloud runtime for AI agents, offering sessions, browser tools, proxies, CAPTCHA handling, persistent identity, and credential injection.

FreemiumCodeAutomation

Daytona

Create isolated programmable computers for coding agents, interpreters, and untrusted workloads

4.1

Daytona provides API-controlled container, VM, Windows, and GPU sandboxes with dedicated filesystems, networking, lifecycle controls, snapshots, previews, and protected secrets.

FreemiumCodeAutomation

Read next

More on Build, Design & Govern