AI NewsInfrastructureAnnouncement

Microsoft's agent sandbox is live on Windows 11 with seven coding agents

Microsoft Execution Containers reached general availability on Windows 11 at Microsoft's Surface event, with OpenAI Codex, GitHub Copilot, Replit, LM Studio, OpenClaw, OpenShell and Unsloth AI shipping support today.

AI News

Editorial3 min read

LinkedInX
Hero image from Microsoft's hybrid intelligence announcement

Image: Microsoft

Why it mattersA Windows user can now run several of the common coding agents inside the same system-level containment layer, so an organisation can set one file and network policy for agents instead of one per tool.

A Windows user can finally sandbox most of the coding agents in daily use with one system-level containment layer, instead of trusting each agent's own guardrails. Microsoft Execution Containers (MXC) reached general availability on Windows 11 at Microsoft's Surface event on 7 October, Microsoft says, with seven agents supporting it on day one and ten more publicly committed. The company says MXC lets organisations define which files and networks an agent can touch, and the operating system enforces those policies at run time.

The seven live on Windows 11 today are Codex from OpenAI, GitHub Copilot, OpenClaw, Replit, LM Studio, OpenShell from NVIDIA, and Unsloth AI, according to Microsoft. The ten the company names as committed to shipping MXC support are Anthropic's Claude Code, Box, Egnyte, Heidi Health, Hermes Agent from Nous Research, Manus, Perplexity, Raycast, Simular, and Meta's Muse as a native Windows app. Microsoft says MXC also works on other operating systems but that Windows integrates it more deeply, with four containment levels: process isolation, session isolation, WSLc and virtual machines, plus Windows 365 for Agents.

Local models the OS actually runs

Microsoft paired the sandbox announcement with four local model announcements that let these agents run without a cloud call. The company says MAI Code 1.1 Flash, a 137-billion-parameter model with 6.8 billion active, now runs locally at 3-bit precision, which cuts the model file by nearly 80 percent and keeps a 256,000-token context window on device. An upcoming NVIDIA Nemotron model with more than 70 billion parameters runs at 2-bit precision in just over 20 GB of memory, Microsoft says, and DeepSeek V4 Flash, a 284-billion-parameter model, also runs locally on the new RTX Spark hardware.

GitHub's HydraFusion router, which previously routed each task between cloud models, now routes between cloud and these local models. Microsoft says Hybrid intelligence through HydraFusion comes to GitHub Copilot, Copilot CLI, and Visual Studio Code in experimental preview later in October. Windows ML, the runtime that executes these local models, now supports llama.cpp, giving developers access to any model packaged in that format.

What Copilot gets

Copilot on Copilot+ PCs gains three local capabilities, Microsoft says: it can read files and recent activity for context with the user's permission, take actions through local Autopilot, and route work between a local and a cloud model. Microsoft's EVP of Copilot, Jacob Andreou, showed a tax-filing demo on stage: an email from an accountant triggered Autopilot to search folders, find the right documents, rename the files, zip them, and draft a reply. These features ship over "the next couple of months," according to Microsoft.

Windows Search on the taskbar is also getting inline actions, Pavan Davuluri said at the event, so a user can toggle dark mode, raise the microphone volume with a slider, or send a text from the search bar. That change ships this fall on Windows 11 PCs.

Microsoft is cross-selling a lot in one announcement: new Surface hardware, a new Copilot story, new local models, and the sandbox platform. The sandbox is the piece a working team can act on this quarter, because a Windows IT policy that defines what any agent can read and reach is more durable than seven different agent-specific controls.

Source

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX