Daniel Reyes, YuSMP Group
Daniel Reyes Principal Engineer, AI/ML, YuSMP Group · agentic and retrieval systems in production for US and EU teams
A laptop on a dark desk with four tall frosted glass cylinders rising from the keyboard, each containing a single glowing blue stream of light, illustrating isolated containers for software agents

The launch in brief

On 7 October 2026 Microsoft made Execution Containers generally available on Windows 11, turning agent sandboxing into an operating-system feature rather than something each agent vendor builds on its own. The announcement came at Microsoft’s Windows and Surface event in San Francisco, alongside new Nvidia RTX Spark PCs.

“We needed to make the desktop the most secure place for agents to execute,” CEO Satya Nadella said, according to Reuters. Windows chief Pavan Davuluri said Anthropic, OpenAI and Nvidia will use the tooling.

For companies that commission or build AI agents for internal workflows, this changes the security conversation: buyers can now ask a concrete question — does your agent run inside MXC, and what does its policy allow? — instead of relying on vendor assurances.

What is Microsoft Execution Containers?

MXC is a policy-driven execution layer built into Windows. A developer or IT administrator writes a policy that lists what an agent, or the code it generates, may read, write, call over the network or launch. Windows then runs the agent inside a container that enforces that policy, rather than trusting the agent to police itself.

The containment is graded. Lightweight tasks can run with process and session isolation, which separates the agent from the user’s desktop, clipboard and input devices. Heavier or riskier work can move into a WSL container, a virtual machine or a cloud-hosted Windows 365 for Agents instance. Microsoft says integration with Agent 365 brings Defender, Entra, Intune and Purview controls to agents running on Windows, so identity, data protection and audit can follow the agent.

When Microsoft unveiled Project Zenith in September, MXC was an announced component of a developer-PC programme. General availability makes it something enterprise IT can actually require.

Which agents already support MXC?

Microsoft lists seven agents with support at launch: OpenAI’s Codex, GitHub Copilot, the open-source OpenClaw, Replit, LM Studio, Nvidia’s OpenShell and Unsloth AI. A longer list has announced support as coming, including Anthropic’s Claude Code, Box, Egnyte, Heidi Health, Nous Research’s Hermes Agent, Manus, Perplexity, Raycast and Simular. Meta’s Muse personal agent is due as a native Windows app with MXC integration.

That breadth matters more than any single feature. Coding agents that execute shell commands on developer laptops are the highest-risk category on most corporate endpoints today, and the largest vendors in that category have now aligned on one OS-level boundary.

What is still missing?

GA of the runtime does not mean the full management story is finished. Reporting on the launch notes that centrally managed MXC policy through Intune and Agent 365 controls is still rolling out, so in the near term the agent developer often defines the boundary. Stronger hardware-backed isolation options are also less mature than the default process-level containers.

MXC also covers Windows endpoints only. Agents running on macOS developer machines, in CI runners or in your own cloud services still need their own sandboxing, secrets handling and egress control.

What it means for US & EU software teams

Least privilege becomes testable. An MXC policy is a declarative artefact: it can be reviewed, versioned and diffed like any other configuration. Security teams can ask to see it during procurement, and auditors can compare it with what the agent actually does.

Agent vendors will be asked about it. If you sell or build an agent that runs on corporate Windows machines, expect questionnaires to ask whether it supports MXC, which isolation level it uses by default and what network destinations its policy permits. Having a precise answer shortens enterprise security reviews.

Compliance evidence gets easier. For EU teams working under GDPR, NIS2 or DORA, and US teams preparing for SOC 2, runtime-enforced file and network boundaries are a cleaner control than written policies alone. They limit what a prompt-injected or misbehaving agent can exfiltrate, which is the scenario regulators and customers now ask about.

It is a layer, not the whole defence. MXC limits blast radius; it does not stop an agent from misusing access it was legitimately granted. Tool permissions, approval steps for destructive actions, logging and prompt-injection testing remain the agent builder’s job.

What to do now

  1. Inventory agents on Windows endpoints — coding assistants, desktop automations, local model runners — and check which already support MXC.
  2. Write the policy you would want to audit: explicit folders, explicit network destinations, no broad home-directory or credential-store access.
  3. Pick the isolation level by risk — process isolation for read-mostly helpers, a VM or Windows 365 for agents that execute untrusted generated code.
  4. Plan for central management through Intune and Agent 365 as those controls roll out, and track policy changes in version control meanwhile.
  5. Keep testing the agent itself for prompt injection and over-broad tool access; containment reduces damage but does not prevent misuse.

Frequently asked questions

What is Microsoft Execution Containers (MXC)?

MXC is a Windows feature, made generally available on Windows 11 on 7 October 2026, that runs AI agents and the code they generate inside an OS-managed container. A policy declares which files, network destinations and processes the agent may use, and Windows enforces it at runtime.

Which AI agents support MXC?

At launch Microsoft listed OpenAI Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, Nvidia OpenShell and Unsloth AI. Anthropic Claude Code, Box, Egnyte, Heidi Health, Hermes Agent, Manus, Perplexity, Raycast and Simular have announced support as coming.

What isolation levels does MXC offer?

Microsoft describes a range from process and session isolation, through WSL containers and virtual machines, up to Windows 365 for Agents in the cloud. Teams can match the level of containment to how risky the agent’s tasks are.

Does MXC make AI agents safe on its own?

No. MXC limits what an agent can reach if it misbehaves or is manipulated, but it does not stop misuse of access that was legitimately granted. Teams still need scoped tool permissions, approval steps for destructive actions, logging and prompt-injection testing.

Sources

Windows Experience Blog, Pavan Davuluri — Building Windows for hybrid intelligence (7 October 2026)
Reuters, Stephen Nellis — Microsoft brings more AI to PCs as it challenges Apple (7 October 2026, via The Spokesman-Review)
TechCrunch — Microsoft releases new Nvidia-chip AI PCs with revamped Windows 11 (7 October 2026)
VentureBeat — Microsoft launches MXC, an OS-level sandbox for AI agents (June 2026)