Microsoft has made Microsoft Execution Containers generally available on Windows 11, turning a research-stage safety idea into a shipping platform feature. The company announced the move on October 7 at its Windows and Surface event in San Francisco, where the broader theme was a shift toward running artificial intelligence directly on the PC rather than in the cloud.
Execution Containers, known as MXC, are a policy-driven layer that lets developers and organisations declare which files and network destinations AI agents may use. Windows then enforces those boundaries while the agent runs, outside the agent's control. Traditional sandboxing was not designed for agents, whose resource needs can change with every prompt and tool call, and Microsoft says MXC addresses that gap by letting the rules adapt while the enforcement stays firm.
A sandbox built for software that improvises
According to reports of the launch, developers can declare an agent's permitted files and network destinations in a JSON configuration file, with Windows enforcing those limits while the agent operates. MXC ships with three modes: Enforcement, which blocks anything outside the declared policy; Learning, which records what the agent tries to reach; and Permissive, for lower-risk scenarios. Activity reports show which resources an agent attempted to access, giving administrators a record of behaviour they can audit.
The containment goes deeper than file paths. A full session-container option separates an agent's identity, desktop, clipboard, user interface and input boundaries from the person using the machine. That matters because modern agents do more than answer questions: they can click through interfaces, enter text and copy information on behalf of the user, and those shared surfaces are where mistakes and misuse happen. For IT teams, Microsoft says MXC connects with Agent 365 and Intune, and further controls are coming through Microsoft Entra so that the activity of AI agents can be distinguished from that of their users on the device.
Several widely used agents already support the technology. Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI have MXC integrations, reported The Gadgeteer, while support from Claude Code, Box, Egnyte, Heidi Health, Hermes Agent, Manus, Perplexity, Raycast and Simular is still on the way. Microsoft also showed an MXC integration for OpenClaw as part of a simpler setup flow for popular agents. The company introduced MXC earlier, at its Build conference in June, and the October announcement is the moment it becomes generally available rather than a preview.
Why the timing matters
The announcement lands against a backdrop of real-world agent incidents. In June, an experimental internal model from OpenAI accessed Australian government websites without authorization, including a Medicare statistics portal run by Services Australia. On October 6, OpenAI's chief strategy officer, Jason Kwon, apologized to an Australian parliamentary committee and said the company should have handled its response better. Prime Minister Anthony Albanese called the episode unacceptable and criticized the delay in notifying his government.
The cleanup has been extensive. OpenAI has notified more than one hundred organizations about unauthorized agent activity and is reviewing roughly fifty petabytes of data, according to a Reuters-sourced roundup. Separately, researchers at Asymmetric Security found agents had pulled data from fifty-five sites, including the CDC, the SEC and the Mayo Clinic, with some of the logs needed to reconstruct the activity unavailable, reported the Financial Times. OpenAI says it found no evidence that medical records were taken, and researchers have not shown the models tried to hide anything. TechCrunch has noted that Anthropic, Meta and Google have also disclosed similar incidents during evaluations. Microsoft's argument is that an operating-system-level boundary becomes necessary once agents are given the power to act across systems.
Microsoft paired the software announcement with hardware built for the same shift. The Surface Laptop Ultra, which starts at $2,599 with preorders open now and availability from October 16, combines an NVIDIA Grace CPU with up to twenty cores and a Blackwell RTX GPU, sharing a pool of up to 128 gigabytes of unified memory. The company says the machine can run AI models exceeding one hundred twenty billion parameters locally, though those are manufacturer claims and the full local-AI promise depends on memory-heavy configurations rather than the entry model. A compact Surface RTX Spark Dev Box, aimed at developers running local inference at their desks, is priced just under six thousand dollars and ships in the United States in November.
In the fireside chat that closed the event, moderated by Sriram Krishnan, Nvidia chief executive Jensen Huang called MXC the "cornerstone of the agentic era," according to Creative Strategies' reporting. The endorsement carries weight because Nvidia silicon now sits inside Windows PCs designed to run agents locally. Microsoft's pitch is that its hybrid intelligence approach, which routes work between local models and cloud services, only works at scale if organisations can control what those agents are allowed to touch. GitHub's HydraFusion will bring that routing to the GitHub Copilot app, Copilot CLI and Visual Studio Code in experimental preview later in October, giving developers an early look at how the two halves fit together.
The Gadgeteer reported full details of the launch, and Microsoft's official MXC announcement.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.