Skip to content
D-CSIL

AI News · 2026-10-09 · 8:00 PM CT

Windows finally cages your AI agents

TL;DR

On October 7, Microsoft made Execution Containers (MXC) generally available on Windows 11: AI agents now run inside OS-enforced boundaries that limit which files and networks they can touch — and the agent cannot rewrite its own permissions. OpenAI’s Codex, GitHub Copilot, and OpenClaw already support it; Claude Code is on the way. At the same event, Microsoft opened pre-orders on a $2,599 Surface Laptop Ultra and a $5,999 dev box that run 120B-parameter models locally.

A laptop on a white desk with a code editor open on its screen
Photo: Pexels

What shipped

At its Windows and Surface event in San Francisco on October 7, Microsoft made Microsoft Execution Containers (MXC) generally available on Windows 11. The announcement came from Pavan Davuluri, executive vice president of Windows and Devices, in a Windows Experience Blog post framing Windows as the home for “hybrid intelligence” — agents that run locally when it makes sense, reach the cloud when they need to, and operate with the security and manageability organizations expect.

MXC is the containment layer of that plan: organizations and developers define which files and networks an AI agent is allowed to use, and Windows enforces those limits while the agent runs. The policy lives outside the agent workload’s control, so the agent, its generated code, a plugin, or a tool cannot grant itself more access when it hits a restriction. First introduced at Microsoft Build in June 2026, the MXC code is MIT-licensed.

How the cage works

Developers declare what a workload needs — files, network destinations — through a unified JSON configuration schema and a multi-language SDK, and MXC maps those controls onto containment backends. Options range from process isolation up to a session container, WSLc, virtual machines, and Windows 365 for Agents. The code runs on Windows, macOS, and Linux, though the session container — a separate OS-isolated session with its own agent identity, desktop, clipboard, UI, and input boundaries — is Windows-only.

Three modes cover the rollout: Enforcement blocks violations outright, Learning watches and reports, and Permissive gets out of the way. Only on Windows can MXC produce an agent activity report showing which resources a workload attempted to use, which is the practical starting point for writing least-privilege policies. One footnote from the coverage: a Windows Update is required, and availability timing varies by device, market, and silicon.

Who is already inside

The agent list on day one is the part that makes this real. Already supporting MXC: OpenAI’s Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA’s OpenShell, and Unsloth AI. Planning support: Claude Code, Box, Egnyte, Heidi Health, the Hermes Agent from Nous Research, Manus, Perplexity, Raycast, and Simular — and Meta’s Muse personal AI agent is coming as a native Windows app with MXC integration.

On the management side, Microsoft says Windows will soon let Microsoft Entra distinguish agent activity from user activity inside Agent 365, with Intune policy for MXC process containers on Windows 11 following. That closes the loop IT departments need: containment limits what an agent can reach, identity records which agent acted, and management tools govern it at scale.

The hardware half

Containment was only half the event. Microsoft opened pre-orders for the Surface Laptop Ultra ($2,599, ships October 16) and the Surface RTX Spark Dev Box ($5,999, ships in November) — both built on NVIDIA’s RTX Spark chip with up to 128GB of unified memory, which Microsoft says is enough to run AI models above 120 billion parameters locally. The Dev Box targets developers: up to a petaflop of AI performance and 2TB of removable storage on the desk.

Microsoft is shrinking its own models to fit: MAI Code 1.1 Flash (137 billion total parameters, 6.8 billion active) uses 3-bit precision to cut its size by nearly 80% while keeping a 256K-token context window, and an NVIDIA Nemotron model over 70 billion parameters is quantized to 2-bit to fit in about 20GB. GitHub’s HydraFusion will route work between cloud and on-device models in experimental previews for the Copilot app, CLI, and VS Code later in October, and Windows ML is gaining llama.cpp support across GPU, NPU, and CPU.

What to do about it

If you run coding agents on Windows machines, start with Learning mode: let MXC’s activity report show you what your agents actually try to touch, then write the Enforcement policy from that evidence instead of guessing. If you build agents, the MIT-licensed code and JSON schema mean you can wire MXC in without waiting for Microsoft to certify your stack — and check whether the agents you already use (Codex, Copilot, OpenClaw) have the support switched on.

Do not buy the hardware expecting the full story on day one. The Copilot features powered by “hybrid intelligence” — local file context, local actions, local models — begin rolling out “in the coming months,” and GitHub’s local-cloud routing is still an experimental preview. Microsoft’s own framing for the purchase is budget math: more than 2 trillion inferences now run locally each month across Copilot+ PCs, and over 40% of business laptops being built are Copilot+ PCs — local compute is where part of your cloud bill can go to die.