Radar / AI security / Microsoft Execution Containers
Microsoft Execution Containers (MXC) goes GA on Windows 11
At its Oct 7 Windows AI event with NVIDIA, Microsoft announced general availability of Microsoft Execution Containers — OS-level infrastructure that runs AI agents in policy-enforced containers, so IT can define which files and networks an agent may access, with Codex, GitHub Copilot and OpenClaw already supporting it.
Why it matters
Makes the OS the sandbox: least-privilege rules for agents are enforced by Windows outside the agent's control, so an agent cannot grant itself more access — a concrete answer to enterprise IT's biggest objection to desktop agents.
What you could build with it
An indie developer selling a Windows desktop automation agent could ship it with MXC containment so each customer's agent runs under an OS-enforced least-privilege profile — a credible answer to enterprise security reviews without building custom sandboxing from scratch.
Does it hold up?
Genuinely usable now — GA on Windows 11 with real agents (Codex, Copilot, OpenClaw) already integrated; independent admin feedback is still pending, but the containment model is concrete and testable today.
Built with Microsoft Execution Containers
- Microsoft Secures AI Agents in Windows 11 (EM360Tech)article · Independent writeup of the MXC GA announcement and its least-privilege containment model for autonomous agents.
- Microsoft brings hybrid AI and agent controls to Windows (TestingCatalog)article · Launch-day coverage: MXC containment plus agent identity and management via Agent 365 and Intune, with Codex, Copilot and OpenClaw as launch agents.
Learn more
First spotted on article: source.
More AI security
OpenAI, Anthropic and Google DeepMind jointly unveil cyber-focused safety models and safeguardsThe three rival labs disclosed weeks of behind-the-scenes coordination and jointly released a set of cyber-focused AI…security · JEV 0.73OpenAI textGrain watermarking for ChatGPT and Codex in the EUOpenAI will roll out its invisible textGrain watermarking system to ChatGPT/Codex users in the EU over the coming…security · JEV 0.65Cloudflare security-audit-skill: multi-phase security audits for coding agentsA coding-agent skill that runs multi-phase security audits with independently verified, machine-checkable findings.security · JEV 0.63LiveNerf: a pre-registered benchmark for post-release model driftOpen-source, pre-registered 30-day benchmark that detects whether Claude Opus 5.5 quietly gets worse after launch.security · JEV 0.61Sandlock 0.8.8: deferred commit for agent sandboxesThe process-based Linux AI sandbox (no container, no VM) ships deferred commit: every run returns a changeset of what…security · JEV 0.58OpenAI disrupts Moonshot-linked 'adversarial distillation' campaignOpenAI disclosed it shut down a coordinated campaign by 15,000+ users to extract hidden model reasoning, attributing a…security · JEV 0.58
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.