Andrew Ng Just Released OpenWorker: An Open-Source, Local-First Desktop AI Coworker That Returns Finished Deliverables Instead of Chat
Here are some key takeaways:
1. The approval layer is typed, not cosmetic
Most desktop agents bolt approvals onto the UI. OpenWorker classifies every tool call into one of four risk classes before it runs:
→ read — no side effects, always allowed
→ write_local — mutates the workspace, path-scoped
→ exec — runs commands
→ external — side effects off the machine
Five permission modes then decide what happens: discuss, plan, interactive (default), auto, custom.
2. Unattended ≠ more autonomous
Unattended mode doesn't raise the autonomy ceiling. It only reroutes approval prompts to an Inbox and suspends the run until a human answers. Autonomy and attention are separate axes — most agent frameworks conflate them.
3. No inference service, by design
You bring a key or run local:
→ 30 curated models, 13 providers
→ Native OpenAI / Anthropic / Google, open-weight via Together and Fireworks
→ Fully local via Ollama, no key
→ Matrix limited to tool-calling models — anything else stalls the agent loop
The stack
→ Tauri 2 + React shell over a local Python FastAPI server (127.0.0.1:8765)
→ 35 connectors live, plus any MCP server
→ Built on aisuite, ~32.4k lines of Python, 78 test modules
Full analysis: https://www.marktechpost.com/2026/07/23/andrew-ng-just-released-openworker-an-open-source-local-first-desktop-ai-coworker-that-returns-finished-deliverables-instead-of-chat/
Repo: https://github.com/andrewyng/openworker
Project: https://openworker.com/
Post #2556
156