Microsoft unveils Windows 'hybrid intelligence' with agent controls
Microsoft announced a Windows strategy built around "hybrid intelligence," letting Copilot and third-party agents run each task locally or in the cloud while remaining under user and IT control. Microsoft Execution Containers (MXC) are now generally available on Windows 11, enforcing file and network access policies at runtime, with agent identity and management handled through Agent 365 and Intune; Codex, GitHub Copilot and OpenClaw already support MXC, while Claude Code, Perplexity and Raycast are due to follow and Meta's Muse for Windows is coming as a native app with MXC integration. Microsoft also detailed MAI Code 1.1 Flash (3-bit precision, nearly 80% smaller, 256K local context window), llama.cpp support in Windows ML, GitHub HydraFusion cloud/on-device routing, and local-AI hardware including the Surface Laptop Ultra (up to 128 GB unified memory, pre-order, October 16) and DGX Station for Windows systems for models up to one trillion parameters.
Why it matters: It signals that agent containment and identity, not just model quality, are becoming the platform battleground on Windows.
Microsoft has unveiled a Windows strategy built around “hybrid intelligence,” combining local and cloud AI so agents can run each task where it belongs while staying under user and IT control. The push spans Windows 11, Copilot+ PCs, developer tools and computers for local AI workloads.
We’re supercharging Copilot on Windows with Hybrid Intelligence.
With your permission, Copilot can tap into the context on your PC, take action for you, and use local models when it makes sense, giving you more capability while helping your tokens go further. pic.twitter.com/7YvqHh8RKT
— Satya Nadella (@satyanadella) October 7, 2026
Microsoft Execution Containers are now generally available on Windows 11. MXC lets organizations define which files and networks an agent may access, with policies enforced at runtime. It pairs containment with agent identity and management through Agent 365 and Intune, allowing IT to separate an agent’s actions from those of the device user. Codex, GitHub Copilot and OpenClaw already support MXC. Claude Code, Perplexity and Raycast are due to follow, while Meta’s Muse for Windows is coming as a native app with MXC integration.
Microsoft is also moving larger models onto PCs. MAI Code 1.1 Flash uses 3-bit precision to cut its size by nearly 80% while retaining a 256K local context window. Windows ML is gaining llama.cpp support across GPU, NPU and CPU. GitHub HydraFusion will route work between cloud and on-device models in experimental previews for the GitHub Copilot app, GitHub Copilot CLI and Visual Studio Code later in October.
— Microsoft AI (@MicrosoftAI) October 7, 2026
With permission, Copilot will use this hybrid layer on Copilot+ PCs to draw on local files and recent activity, perform Windows actions and call models running on the device. The capabilities are expected to begin rolling out in the coming months across Copilot Home, Code and Autopilot.
A new generation of Surface is here. pic.twitter.com/TEsVzs8Pma
— Microsoft Surface (@surface) October 7, 2026
The hardware plan ranges from always-on mini PCs to RTX Spark builder machines and DGX Station systems. Surface Laptop Ultra, with up to 128 GB of unified memory and support for models above 120 billion parameters, is available for pre-order and arrives October 16. DGX Station for Windows systems supporting models up to one trillion parameters are due later this year. Windows Search actions will also let Insiders toggle settings, manage windows and send messages from the taskbar. Microsoft is tying Windows, Copilot, GitHub, Surface and NVIDIA hardware into one platform for secure agents and local AI, from personal PCs to shared enterprise compute.
Sources and related context
- Microsoft Execution Containers: Policy-driven containment for AI agents: Supports: The developer announcement confirms MXC's general availability and runtime enforcement of file and network access policies.
- Bringing local models and sandboxed tools to Windows and GitHub Copilot: Related context: The technical deep dive explains MAI Code 1.1 Flash's local memory requirements and Copilot's automatic routing and explicit local model selection.
How we got here
- Could you stop a rogue AI agent from escaping? TechRadar's sci-fi security quizTechRadar · Meta Muse
- Ex-White House AI adviser Sriram Krishnan raising ~$500M AI venture fundThe Information · Microsoft
- Replit launches desktop app preview for Windows with Microsoft and NVIDIA sandboxingReplit · Microsoft
- Microsoft's Copilot gains local file access and OS-wide actions in WindowsThe Verge AI · Microsoft
- Microsoft is turning Windows Search into a chatbot this fallEngadget AI · Microsoft
- GitHub adds AI secret detection to push protection, blocking leaks in under 2msGitHub Blog · AI & ML · Microsoft