Microsoft is changing how autonomous AI agents operate on Windows, introducing new security controls designed to stop them from accessing files, applications and other resources without permission.

Announced at a Microsoft and Nvidia event in San Francisco on 7 October 2026, the changes centre on Microsoft Execution Containers (MXC), a technology that allows AI agents to work inside restricted environments rather than automatically sharing a user's access to their computer. 

Microsoft has made MXC generally available on Windows 11, alongside new tools for managing AI agents and hardware designed to run more powerful AI models directly on PCs. The announcement brings together two parts of Microsoft's plans for AI-powered computing: giving agents more work to do while placing clearer limits on what they're allowed to access.

em360tech image

Microsoft Introduces Security Controls for AI Agents

Unlike a traditional chatbot, an autonomous AI agent can do more than respond to questions. It can use applications, work with files, write code and complete tasks on someone's behalf, sometimes without needing a person to approve every step.

That becomes a security concern when an agent has access to more information or systems than it needs. An agent working on a software project, for example, might need permission to edit the project's code. It shouldn't necessarily be allowed to change the settings of the server where that software runs.

MXC is designed to make that distinction enforceable. Developers specify which resources an agent needs, and the container restricts its activity accordingly. The security rules are maintained outside the agent's control, meaning it can't simply give itself additional permissions when it encounters a restriction.

Microsoft says the technology can contain an entire agent or individual parts of its work, including generated code and tools. It supports Windows 11, macOS and Linux, although some isolation features are exclusive to Windows.

How Windows Will Keep AI Agents Under Control

MXC supports different levels of isolation depending on the tasks an agent needs to perform. Some agents can run in restricted processes, while others can operate in separate desktop sessions that prevent them from freely interacting with the user's normal working environment. 

For example, an agent working in an isolated session won't automatically have access to everything an employee has open on their desktop. Its access to resources such as files, network connections and the clipboard can be restricted according to the environment and policies in place. Microsoft has also introduced different ways to test and enforce those policies. 

Developers can observe which resources an agent attempts to access before deciding what to allow, then apply restrictions that block actions outside those limits. The company says the approach is intended to work with agents from different providers, rather than requiring organisations to use Microsoft's own AI tools. 

GitHub Copilot, OpenAI Codex and Nvidia OpenShell are among the tools Microsoft identifies as supporting MXC. Other developers, including Anthropic, are expected to add support.

Microsoft Plans More Control for Enterprise IT Teams

Microsoft is also extending its security approach beyond controlling what agents can access. The company wants organisations to identify which agent performed an action and manage its permissions separately from those of the employee using the device. 

To support this, Microsoft plans to integrate agent identity with Microsoft Entra and extend Microsoft Agent 365 management to agents running locally on Windows. The company is also working on Intune controls that would allow IT administrators to apply restrictions and monitor activity across managed devices.

These capabilities could help security teams investigate an agent's behaviour or restrict a compromised agent without removing the employee's access to company systems. Not all of these features are available yet. 

Microsoft says the additional identity and management integrations are coming soon, while MXC itself is generally available. Support for MXC on Windows 365 Cloud PCs is also generally available. Several AI tools already support MXC, including GitHub Copilot, OpenAI Codex, OpenClaw, Replit and Nvidia OpenShell. 

Anthropic Claude Code, Manus and Perplexity are among those expected to add support.

Microsoft and Nvidia Bring More AI Processing to PCs

Are you enjoying the content so far?

The security announcement comes alongside a wider push to run advanced AI directly on Windows computers. Microsoft calls its approach hybrid intelligence, which means combining AI models running locally on a PC with models accessed through cloud services. 

Rather than sending every task to a remote server, software can use the computer's own processing power when it's suitable for the job. The company announced plans to bring models including Nvidia Nemotron and DeepSeek V4 Flash to powerful Windows devices. It also revealed that GitHub's HydraFusion technology will begin testing local and cloud model selection later in October. 

Copilot is getting similar capabilities. Microsoft says upcoming features will allow the assistant to use local files and recent activity with permission, carry out tasks on a user's computer and choose local processing where appropriate. The new features are expected to begin rolling out to Copilot+ PCs over the coming months. 

Microsoft and Nvidia also unveiled the Surface Laptop Ultra, powered by Nvidia's RTX Spark platform. The laptop starts at $2,599 and is scheduled to become available on 16 October. It's designed for demanding AI workloads, including running large models directly on the device.

Final Thoughts: Windows Is Preparing for More Autonomous AI

Microsoft's latest Windows announcement puts security controls alongside the growing ability of AI agents to work independently on users' computers. MXC gives developers a way to restrict agent activity today, while the planned identity and management integrations aim to give businesses more control as they introduce these tools across their organisations. 

The distinction between what's available now and what's still being developed is important. Microsoft has released the containment technology, but some of the broader enterprise controls it has announced will arrive later.