Microsoft wants AI agents to run on PCs more often
New Windows capabilities combine local models with containers that restrict agents' access to files and networks.
Microsoft is stepping up its focus on AI that runs directly on Windows devices. The company is linking local models to isolated execution environments, allowing agents to perform tasks without continually sending data to the cloud.
Microsoft presents the approach as a way to make AI agents more useful and manageable. Agents can not only provide answers, but also read files, run code or launch actions in applications. That is precisely why questions arise over which data they can access and how organisations can monitor their actions.
The Windows agent environment uses Microsoft Execution Containers, among other things. The technology is intended to isolate agents from the rest of the system. Microsoft describes options for process and session isolation, access rules for files and network restrictions. Agents also receive a separate identity, making it clearer which action was carried out by a person and which by software.
Microsoft Foundry Local also offers models that can run on Windows, macOS computers with Apple Silicon and Linux. According to Microsoft, this can reduce latency, enable offline use and keep sensitive data on the device. That does not mean all AI runs locally: larger models and some services remain dependent on Microsoft's cloud infrastructure.
The announcement fits into a broader hardware strategy. Microsoft is working with Nvidia on Windows devices that can perform more AI calculations locally. Axios described the new devices as an attempt to create a market for computers on which developers and companies can perform more demanding AI tasks without using a cloud model for every action.
For companies, part of the security challenge is therefore shifting to their own workplaces. Local processing can help prevent data leaks and reduce delays, but organisations themselves must ensure updates, model management, logging and the restriction of permissions. An agent running locally is not automatically reliable or secure; a configuration error could instead give it direct access to company data.
Microsoft's plans are therefore primarily an infrastructure and management proposal, not proof that local agents can already work independently on a broad scale. The key test will be whether developers can configure the containers, identities and policy rules easily enough. For Dutch organisations, this is relevant to applications involving personal data, trade secrets and systems covered by European AI and privacy rules.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical description follows Microsoft's own documentation and is supplemented by independent reporting on the hardware strategy. The text makes no unsubstantiated claim about the products' actual security.
- confirmed Microsoft offers a Windows environment for local AI agents with isolation and policy rules. — Described on the official Windows Agentic page. source
- confirmed Microsoft Execution Containers are intended to shield agents. — Explained in the Windows Developer Blog. source
- confirmed Foundry Local supports local models on multiple operating systems. — Microsoft names Windows, macOS on Apple Silicon and Linux x64. source
Editor's note
The technical capabilities are based on Microsoft's documentation. The implications for security and privacy are journalistic analysis; no evidence has been provided that the new systems resolve all risks.Sources
- Windows Agentic — Microsoft
- Windows platform security for AI agents — Microsoft Windows Developer Blog
- Microsoft looks to reboot the AI PC with Nvidia — Axios
More on this in Dutch media
- AD — „microsoft windows”
- RTL Nieuws — „microsoft windows”
- FD — „microsoft windows”