Microsoft Wants to Put Windows AI Agents on a Leash
By Jim McMahonon 10/08/2026 |
![{$insert['content_title']](/content/file/6479_agentsonaleash.jpg
)
AI and Agents are new enough where we are just getting our arms around its capabilities and giving an AI permission to organize a folder should not mean handing it the keys to your entire computer. Microsoft's latest announcement attempts to address that problem, and it's far more useful that than another "sumerize" with AI button.
On October 7, Microsoft announced general availability of Microsoft Execution Containers, or MXC. Developers and IT administrators can use it to limit the files, network connections, and other resources an AI agent can access.
This is a big deal because an AI answering a question and an AI changing files on your computer carry different risks. A bad answer might waste your time. A bad action can delete something, expose information, or leave you with a mess to fix. Or a mess you can't fix like the guy who's agent deleted 48,000 files of historical stock data on him without asking.... Ooopsie!
What Is an AI Agent?
An AI agent goes beyond answering questions. It can use tools and take steps to complete a task, such as editing files, running commands, or working through a software project. Exactly what it can do depends on the application and the permissions it receives.
That makes access control a lot more important. You might trust an assistant to sort copies of your documents. That does not mean you want it wandering through your family photographs or deciding that an unrelated folder needs cleaning up.
How Microsoft Execution Containers Work
In its developer announcement, Microsoft describes a boundary enforced outside the agent's control. The agent cannot grant itself additional access just because it decides that would make the job easier.
This is the sort of behaviors that we have been seeing recently with "rouge" AI hacking things, like Australia.
A policy can distinguish between files the agent may change, files it may only read, and locations it cannot access. It can also restrict network connections. The available isolation depends on the container type and configuration.
Think of hiring someone to paint your kitchen. They need access to the kitchen. They do not need your bank password, the contents of your filing cabinet, or permission to remodel the upstairs bathroom because it would improve the overall result.
The same principle should apply to software that acts on your behalf. Give it enough access to do the job, then keep the rest out of reach. Seems reasonable.
Does This Protect Every AI App Automatically?
Microsoft Execution Containers is primarily technology for developers and IT administrators. There is no universal Windows Settings switch that puts every AI app on a leash. Applications must integrate it, and developers decide how those permissions are presented to users. Before trusting an agent with your files, check what its particular application actually restricts.
This announcement should not be read as a promise that every AI application on Windows now runs inside these limits. The application needs to integrate MXC, and its configuration matters.
Microsoft documents enforcement and learning modes that block ungranted access. It also offers a permissive mode that records access the policy would have denied but allows it to proceed. That can help developers build a policy, but recording an action and stopping it are different things.
For example, an agent summarizing documents could receive read-only access to the originals and permission to save its summaries in a separate folder. Your photographs could be explicitly blocked. The important part is that these permissions are enforced by the containment system, rather than relying on a prompt that says, “Please don’t touch my other files.”
It would look something like this:
{
"filesystem": {
"readonlyPaths": [
"C:\\AI-Workspace\\Source-Documents"
],
"readwritePaths": [
"C:\\AI-Workspace\\Finished-Summaries"
],
"deniedPaths": [
"C:\\Users\\Jim\\Pictures"
]
}
}
Microsoft's broader Windows announcement describes a mix of local and cloud AI capabilities. Additional agent identity and management features remain on the roadmap.
What Should You Check Before Clicking Allow?
Look, software is changing and agents are becoming more and more everyday and you need to stay vigilant. Before giving an agent access, look for answers to three basic questions:
- What can it read or change? Access should match the task, with a clear distinction between viewing files and modifying them.
- Where can it send information? Working with local files does not necessarily mean the entire task stays on your computer.
- What happens when it needs more access? The application should explain the limitation and make any request for additional permissions understandable.
Start with copies of ordinary files and a task whose results you can easily check. A permission boundary may keep an agent away from unrelated folders, but it cannot stop the agent from making a bad edit to a file you allowed it to change. Backups still matter.
Geek Verdict
This is a surprisingly sensible direction. If software can act on our behalf, its limits should be enforced by something more reliable than asking the AI to behave itself and we should be aware of those limits prior to using them.
The real test is how applications present those limits. Regular users should be able to understand what they are authorizing without reading developer documentation. Clicking "Allow" should tell you exactly what you are allowing.
|
Jim McMahon
Jim McMahon, aka Corporal Punishment, is the founder of MajorGeeks.com. He has spent decades testing software, troubleshooting Windows, and helping users cut through the nonsense. He loves real freeware, hates bloatware, and runs on caffeine, sarcasm, and questionable choices. |




