How Microsoft Is Trying to Keep Your AI Agents Contained

how-microsoft-is-trying-to-keep-your-ai-agents-contained

Written by

in

by: Katelyn Chedraoui | CNET

If you’ve read even one news story from the AI industry recently, it’s probably been some version of this: An AI agent, or bot, from a major lab got out of its testing environment and found its way onto the internet, hacking real websites. That’s because it’s happened to several major AI companies (including Meta, OpenAI and Anthropic), with hacked sites including the AI platform Hugging Face and sites operated by the US and Australian governments.

To help prevent these kinds of agent-driven cybersecurity breaches, Microsoft is betting on new enterprise software to corral AI agents.

They’re called Microsoft Execution Containers, or MXC, and they live in your developer’s sandbox on Windows. They have two main purposes: to identify and then restrain AI agents. Using these “containers” — which are really just a layer of software applied on top of your existing work — helps you limit what files and network designations your AI agent can access. CEO Satya Nadella said on Wednesday that MXC is now generally available during the company’s Surface Laptop Ultra event.

Microsoft Unveils New Surface Laptop Ultra and New AI Agents

The idea is that your AI agent will get in less trouble — and cause less damage — if it only has access to specific files and designations on your laptop. Windows developers can choose from three levels of access to grant their AI agents. The recommended level gives your agent access to the internet (essential for many agentic tasks) as well as limited access to areas of your PC, such as your downloads, documents and desktop.

Photo of the MXC security levels, three options reading Locked Down, Recommended and Unprotected
Locked Down mode is like a kill switch for your AI agent’s access. Unprotected is “YOLO mode,” and the Recommended option gives the agent limited access.Katelyn Chedraoui/CNET

The most restrictive mode is Locked Down, which can serve as a kind of kill switch for access. It restricts your agent’s access to the internet and your files. Unprotected is the complete opposite and gives the AI the most access to your digital ecosystem. You can toggle between them and customize access as needed.

You can also monitor what your agent is doing and how much of your CPU, memory, disk and network you and your AI agent are using. In the example below, the user in the top line is the human logged into Windows. You can see their AI agent (R2-W9 (20)) at work accessing OpenClaw and an Nvidia container.

Photo of a screen showing Users in Windows, one human email and an AI agent called R2-W9 (20). You can see what percentage of CPU, memory, disk and network is being used by each users.
In Windows MXC, you can see what (or who) is using the most memory space: you or your AI agent.Katelyn Chedraoui/CNET

Safety controls like MXC have been and will continue to be essential for AI labs, particularly as personal AI agents like Meta Muse and OpenAI’s dots become more popular. The rogue agent hacks we’ve seen this summer targeted websites, but it’s easy to hypothesize that, as these agents become more widespread and embedded in our systems, the consequences could easily bleed into the real world.

AI Atlas

For Microsoft specifically, which is focused on hard-selling its AI to enterprise customers, it needs to be able to assure a company that its AI won’t wreak havoc on their business. CEO Satya Nadella rightly said that tech companies like Microsoft will have to earn people’s trust to get them to use its agentic AI tools.

“If you look at the first decision we are making, it’s what … authority that I’m giving to the agent on my behalf?” Nadella said on Wednesday. “And that is a decision that will be based on trust and will keep increasing the more autonomous [AI] is.”

But no AI safety program is totally bulletproof. Part of that is the nature of new technology. But debate over whether the AI industry is doing enough to make AI safe has reached a fever pitch recently. AI experts and the general public are rightly concerned that AI labs’ drive to grow fast and break things could lead to disaster for us all.

At the very least, AI leaders seem to understand that safety is key for AI. Or, they’re including it higher up in their sales pitch.

“It’s about trust. It’s about containment. It’s about monitoring,” Nvidia CEO Jensen Huang said at the event. “If we can’t get that right, that’s the first part.”

Katelyn Chedraoui

Katelyn Chedraoui

Reporter 2

Katelyn is a reporter with CNET covering artificial intelligence, including chatbots, image and video generators. Her work explores how new AI technology is infiltrating our lives, shaping the content we consume on social media and affecting the people behind the screens. She graduated from the University of North Carolina at Chapel Hill with a degree in media and journalism. You can reach her at kchedraoui@cnet.com.