Microsoft launches execution containers to keep AI agents on a short leash

2 hours ago 2



Microsoft wants AI agents to stop wandering into rooms they were never invited to. At its Build 2026 conference on June 2, 2026, the company unveiled Microsoft Execution Containers, or MXC, a security toolkit built to stop agents from reaching data they have no business touching. Agents now write and run their own code on the fly, and the old security playbook was written for software that sat still. What Microsoft actually shipped MXC is a policy-driven SDK, a set of building blocks developers plug into their own software. It applies containment at the operating system level on both Windows and Windows Subsystem for Linux, known as WSL. Developers write access rules for specific resources using JSON or TypeScript policies. The OS kernel then enforces those rules in real time, so the agent cannot simply talk its way past them. Microsoft calls the underlying structure a “composable sandbox.” A sandbox is a walled-off space where code can run without touching the rest of the system. Composable means developers can mix and match the strength of those walls. The isolation tiers span a wide range: Process isolation: the lightweight option, fencing off an individual running program Sessi...

Read Entire Article