AI generates code that will perform "zip all files", but that could be dangerous because "rm -rf *" running on employee laptop is a risk, thus create this disposable desktop for AI to connect and manage, build the code, run the code, then evaluate results, and then destroy the instance.
I personally like it and think every laptop needs to have a read only OS with disposable desktops running for each app. Why does my Outlook need to live in the same world as my IDE?