Create

Sign in to ReadmeX

Sign in to join communities, post, vote and chat.

or

New here?

Story

Microsoft makes its Execution Containers for AI agents generally available

AI summary

At its Surface Laptop Ultra event, Microsoft CEO Satya Nadella said Microsoft Execution Containers (MXC) are now generally available. The software runs in the Windows developer sandbox with two aims — identifying AI agents and restraining them — by limiting which files and network destinations an agent can reach, offering Locked Down, Recommended and Unprotected access levels plus monitoring of agent CPU, memory, disk and network use. Nadella said deciding how much authority to give an agent is a trust-based decision, and Nvidia CEO Jensen Huang said at the same event that "trust, containment, monitoring" come first.

Why it matters: As personal agents such as Meta Muse and OpenAI dots spread, enterprise-grade containment and permission controls are becoming a prerequisite for deploying agents safely.

MicrosoftWindowsMicrosoft Execution Containers

9
Source textCNET · 3 min read

If you’ve read even one news story from the AI industry recently, it’s probably been some version of this: An AI agent, or bot, from a major lab got out of its testing environment and found its way onto the internet, hacking real websites. That’s because it’s happened to several major AI companies (including Meta, OpenAI and Anthropic), with hacked sites including the AI platform Hugging Face and sites operated by the US and Australian governments.

To help prevent these kinds of agent-driven cybersecurity breaches, Microsoft is betting on new enterprise software to corral AI agents.

They’re called Microsoft Execution Containers, or MXC, and they live in your developer’s sandbox on Windows. They have two main purposes: to identify and then restrain AI agents. Using these “containers” — which are really just a layer of software applied on top of your existing work — helps you limit what files and network designations your AI agent can access. CEO Satya Nadella said on Wednesday that MXC is now generally available during the company’s Surface Laptop Ultra event.

Image 1: Microsoft Unveils New Surface Laptop Ultra and New AI Agents

The idea is that your AI agent will get in less trouble — and cause less damage — if it only has access to specific files and designations on your laptop. Windows developers can choose from three levels of access to grant their AI agents. The recommended level gives your agent access to the internet (essential for many agentic tasks) as well as limited access to areas of your PC, such as your downloads, documents and desktop.

Image 2: Photo of the MXC security levels, three options reading Locked Down, Recommended and Unprotected

Locked Down mode is like a kill switch for your AI agent’s access. Unprotected is “YOLO mode,” and the Recommended option gives the agent limited access.Katelyn Chedraoui/CNET

The most restrictive mode is Locked Down, which can serve as a kind of kill switch for access. It restricts your agent’s access to the internet and your files. Unprotected is the complete opposite and gives the AI the most access to your digital ecosystem. You can toggle between them and customize access as needed.

You can also monitor what your agent is doing and how much of your CPU, memory, disk and network you and your AI agent are using. In the example below, the user in the top line is the human logged into Windows. You can see their AI agent (R2-W9 (20)) at work accessing OpenClaw and an Nvidia container.

Image 3: Photo of a screen showing Users in Windows, one human email and an AI agent called R2-W9 (20). You can see what percentage of CPU, memory, disk and network is being used by each users.

In Windows MXC, you can see what (or who) is using the most memory space: you or your AI agent.Katelyn Chedraoui/CNET

Safety controls like MXC have been and will continue to be essential for AI labs, particularly as personal AI agents like Meta Muse and OpenAI’s dots become more popular. The rogue agent hacks we’ve seen this summer targeted websites, but it’s easy to hypothesize that, as these agents become more widespread and embedded in our systems, the consequences could easily bleed into the real world.

Image 4: AI Atlas For Microsoft specifically, which is focused on hard-selling its AI to enterprise customers, it needs to be able to assure a company that its AI won’t wreak havoc on their business. CEO Satya Nadella rightly said that tech companies like Microsoft will have to earn people’s trust to get them to use its agentic AI tools.

“If you look at the first decision we are making, it’s what … authority that I’m giving to the agent on my behalf?” Nadella said on Wednesday. “And that is a decision that will be based on trust and will keep increasing the more autonomous [AI] is.”

But no AI safety program is totally bulletproof. Part of that is the nature of new technology. But debate over whether the AI industry is doing enough to make AI safe has reached a fever pitch recently. AI experts and the general public are rightly concerned that AI labs’ drive to grow fast and break things could lead to disaster for us all.

At the very least, AI leaders seem to understand that safety is key for AI. Or, they’re including it higher up in their sales pitch.

“It’s about trust. It’s about containment. It’s about monitoring,” Nvidia CEO Jensen Huang said at the event. “If we can’t get that right, that’s the first part.”

Read the original →

How we got here

  1. OpenAI's math advances spark a reckoning for academiaBloomberg Technology · OpenAI
  2. Anthropic, Google, Mistral roll out Haiku 5.5, Gemini 4 Argon and moreCNET · Anthropic
  3. NVIDIA showcases GPT-6 Astra agents building Omniverse simulationsNVIDIA Blog · NVIDIA
  4. NVIDIA tutorial: turning CAD into SimReady robot assets with GPT-6 AstraNVIDIA Technical Blog · NVIDIA
  5. Anthropic launches OSS Scanner, free AI security scans for open-sourceTechmeme · Anthropic
  6. Fired OpenAI safety researchers deny misconduct, warn of chilling effectThe Information · OpenAI

Comments

I've used this: share my experience What I think: share my view
How important is this story?No ratings yet

No comments yet. Start the conversation.