2/ Prior work has evaluated alignment in text-only domains. We show that computer-use agents perform misaligned actions much more frequently, even without an adversary (prompt injection, malicious user, etc.), *when misalignment is instrumental to task completion*.