ComputerWeekly

Microsoft tweaks Windows to secure agentic AI


Microsoft has unveiled how it sees the Windows operating system evolving into a platform for locally run artificial intelligence (AI) agents.

Opening the event in San Francisco, Microsoft CEO Satya Nadella said: “I got up this morning and I was thinking about what these launch events mean to all of us. They obviously mean a lot in the moment. They’re about a device; they’re about an operating system update and application. But they’re also trajectories.”

He said the first Windows professional developer conference he attended in 1991 was about the x86 architecture, and for Nadella, it was about Windows on the server. The San Francisco event on 7 October focused on agentic AI in Windows.

Windows is being built out to support this ecosystem. During the event, Microsoft annouced that Microsoft Execution Containers (MXC) is now generally available. This provides what Microsoft calls “a containment layer” to enable IT administrators to enforce policies at runtime that determine which files and other enterpise IT resources an agent has access to.

Agents already supporting MXC include Codex from OpenAI, GitHub Copilot, OpenClaw, Replit, LM Studio, OpenShell from Nvidia and Unsloth AI. Microsoft is also working to add more agents including Anthropic Claude Code, Box, Egnyte, Heidi Health, Hermes Agent by Nous Research, Manus, Perplexity, Raycas and Simular.

Meta’s Muse is also planned to be available as a native app on Windows with MXC integration.

“With containment, identity and manageability built into the platform, Windows helps you control what agents can access, know which agent acted, and govern them at scale,” Pavan Davuluri, executive vice-president for Windows and devices, stated in a blog post.

Davuluri said Microsoft Windows will provide hybrid intelligence, which brings local and cloud AI together. He added that this helps Microsoft customers stretch their budgets while preserving access to the intelligence they need.

Windows is offering “intelligent routing”, between locally run AI inference and publicly hosted AI models. “We’re bringing frontier-class capabilities to local PCs and enabling services like GitHub to route intelligently on Windows,” said Davuluri.

“To bring this to life requires powerful local models, intelligent orchestration, a performant runtime and capable silicon, all working together to create a meaningful experience.”

Microsoft claims the security it is building into Windows makes the operating system the most secure for agentic AI. Divya Venkataramu, director of product marketing at Microsoft, said: “We’re evolving Windows to be the most secure platform for agents.”

According to Venkataramu, Microsoft’s approach has been to separate agent activity from user activity, which she said has been achieved using MXC and the Microsoft security stack. “This separation will allow security teams to evaluate agent behaviour independently from the user behaviour,” she said. “That means access restrictions apply to the agent.”

This level of control to lock out malicious agent activity means users should not be affected.

Using the security built into Windows together with Microsoft Agent 365, she said organisations will be able to understand which agents are running, associate each activity with a specific agent, investigate risky behaviour and apply policies for a single agent or group of agents without relying on user-level data or device-level capabilities.



Source link