Microsoft makes Execution Containers generally available to fence in AI agents
MXC lets developers set what files and networks an agent may use. The rules sit outside the agent, so it cannot give itself more access.
Microsoft released a tool that sets limits for AI helpers that run code on a computer. It decides which files and internet connections a helper can use, and the helper cannot change those rules. It is for people who build these helpers.
Hype check
Quieter than it deserves. This one matters more than the coverage suggests.
Our editorial opinion, based on the sources below. How we score
Your call: hype or real?
Real = it will matter in daily use. Hype = louder than it is. One vote, and it can’t be changed.
Our view and readers’ views are opinions, not statements of fact about a product.
Why it matters
that run code need clear limits. MXC gives builders one policy format across Windows, macOS and Linux.
Skip: nothing changes for you.
The details
- Policies cover files, network, processes and the user interface.
- Backends: process container, session container, WSL container and MicroVM (experimental).
- Modes: enforcement, learning and permissive.
- Agents already supporting MXC include GitHub Copilot, OpenAI Codex, Replit and LM Studio.
- Intune policy is coming soon, and Entra support is coming soon.
Receipts
The company or lab said it. Primary source linked. Open the sources and check us.
Written with the help of AI tools and checked against the sources above. How we work
See a mistake? Tell us and we’ll fix it.