On July 21, 2026, Anthropic shipped Record a Skill inside Claude Cowork, the Mac desktop app. The mechanic is disarmingly simple: an employee records their screen — clicks, typing, and voice narration — and Claude turns the recording into a reusable SKILL.md skill they can invoke again and again. A recording can run for about ten minutes. Anthropic's own documentation is blunt about what gets captured: "Everything on your screen is captured for the length of the session, along with anything you say."
That is a genuinely useful capability. It drops the barrier to AI-assisted automation to roughly zero — any analyst, program manager, or operations lead can now build a reusable AI workflow without writing a line of code.
But here is the governance question nobody is asking yet: who reviews the skill before it gets reused?
The Plan Asymmetry Is the Wedge
Read Anthropic's support docs closely and a strange asymmetry appears. Record a Skill is "available on Pro, Max, and Team plans, in Cowork in Claude for Mac. It isn't available in chat, on Windows, or on Free and Enterprise plans."
Think about what that means for a regulated organization. The plan tier with the most compliance obligation — Enterprise, with SSO, audit tooling, and admin controls — is excluded from the feature. But an employee's personal Pro subscription, running on the same Mac they use for work, is not. The capability with the sharpest governance need is unavailable exactly where governance lives, and available exactly where it doesn't. That is not a bug in the rollout; it is the shape of every shadow-AI problem, compressed into a single feature.
Shadow Automation Is the Third Wave
For a decade, security teams learned to fear shadow IT — employees spinning up SaaS outside procurement. Shadow AI, employees pasting corporate data into personal chatbots, was the second wave. Record a Skill introduces a third: shadow automation.
An employee records a workflow that touches sensitive data. Claude packages it into a SKILL.md. If the organization has turned on skill sharing, that skill can be shared with colleagues or published to an organization directory. And skills are not just prose — Anthropic's docs describe attaching "executable code files to skill.md, allowing Claude to run code." Within days, an AI workflow nobody reviewed for data handling, scope creep, or policy alignment can be running across dozens of sessions.
What the Admin Console Cannot See
Here is the part that should stop a compliance lead cold. On the org-wide sharing path, Anthropic states plainly: "There's no approval workflow for org-wide sharing. If you enable Share with organization, any member can publish a skill to the directory without review."
And the audit trail? "The audit log doesn't capture the contents of shared skills — only the share event itself. There's no admin dashboard to browse or inspect the contents of skills shared between members."
So the record you get is that a skill was shared, not what it does. For most enterprises that is a headache. For a defense contractor, an aerospace OEM, or a program operating under DoD security requirements, it is a different order of problem: an automation that touches controlled data, with no central place to review its contents before it propagates. The video and audio of the original recording are discarded, but Anthropic notes that "a set of screenshots from the session" is retained inside the Cowork task — screenshots of whatever workflow the employee happened to be running.
The Honest Scope of What Any Governance Tool Can Do Here
It would be easy — and wrong — to claim a third-party gateway can reach inside a Cowork session and gate a skill as it records. It cannot. That surface belongs to Anthropic; no external tool, ours included, sits between an employee's Mac and Claude's sandbox. Pretending otherwise is exactly the kind of assurance-without-evidence that got the industry into this position.
That limit is the whole point. If the tool that creates the skill is outside your control, the only governance you can actually rely on is enforcement at the boundaries you do own: the network paths, data stores, and systems a skill's outputs and integrations reach once they leave the sandbox. A policy that lives in a wiki cannot enforce that. An endpoint agent can tell you a tool is running, not whether a specific action was authorized against a specific data context.
Put the Enforcement Where You Own It
The durable lesson of Record a Skill is architectural, and it is the same lesson that matters most as AI moves to the edge and into forward-deployed, disconnected, and air-gapped environments: govern at the boundary you control, deterministically, in real time. A runtime enforcement layer sits at the AI data boundary you own and, for each call crossing it, evaluates the action against your policy and permits or blocks it — with an audit record that survives your next compliance review. It will never see inside Anthropic's console. It governs what crosses into and out of the systems that are yours.
That is the difference between having a policy and enforcing one at the moment of action. The GRC platforms inventory your AI programs. The endpoint tools tell you which AI apps are running. Neither answers the question a program security officer actually has to answer: did this automation touch data it was not authorized to touch, and can I prove what happened? Answering that is the job of the AI Action Enforcement Layer.
The First-Mover Window Is Short
Record a Skill launched three days ago. Within months it will be table stakes for every Claude Team subscriber, and every major LLM vendor will ship a comparable workflow-recording feature. The organizations that decide now where their AI enforcement boundary lives — and put it somewhere they control — will be ahead of the next wave. The ones that treat it like a normal software rollout and wait for the first incident will be reconstructing what a skill did from a log that only recorded that it was shared.
If you want to see where your current AI toolchain leaves the boundary open, the AI Boundary Review is the place to start. Thirty minutes, no commitment. We will walk your actual data paths and show you exactly where an unreviewed skill could cross a line you cannot currently see.