Quick Facts
- Microsoft launched MXC at Build 2026, an OS-level sandbox that controls what AI agents can access with enforcement at the kernel level
- OpenAI, Nvidia, Manus, Nous Research, and OpenClaw are launch partners building on the platform
- Microsoft reported 420 million monthly active Copilot users in Q1 2026, up from 230 million in Q1 2025
Microsoft unveiled Microsoft Execution Containers (MXC) at Build 2026, a policy-driven execution layer built into Windows that lets developers and IT administrators control exactly what AI agents can access. The sandbox enforces boundaries at runtime through the OS kernel.
CEO Satya Nadella said Microsoft wants “Windows to be a fantastic place to run and scale agents.” The announcement addresses a growing enterprise need as Gartner predicts 40% of enterprise applications will include task-specific AI agents by end of 2026, up from less than 5% today.
Five launch partners joined the announcement. OpenAI’s David Wiesen said the partnership allows the company to “explore new patterns for AI agents to safely and efficiently generate and execute code.” Nvidia is bringing its OpenShell framework to Windows built on MXC.
The platform ships with eight containment backends ranging from lightweight process isolation to micro-virtual machines and Linux containers. GitHub Copilot’s command-line interface already uses the lightweight process isolation option.
MXC addresses a critical enterprise problem. Research shows 77% of enterprise teams spend significant engineering time on infrastructure plumbing rather than agent logic. The sandbox provides what Microsoft calls a “composable sandbox spectrum” that scales from basic process containment to full virtualization.
Agent 365, scheduled for preview in July, layers Microsoft’s enterprise tools on top of MXC. The system integrates Entra identity service, Intune device management, Microsoft Defender threat protection, and Microsoft Purview compliance capabilities.
Dillon Rolnick, CEO of Nous Research, said “continuously-running local agents require intentional isolation. Developers need control over what an agent can access and trust that those controls will hold.” His company’s Hermes agent builds on the MXC platform.
The platform aims to solve regulatory challenges for enterprises in financial services, healthcare, and government sectors. These industries need audit trails that distinguish between human actions and agent actions on the same machine.
OpenClaw, the open-source agent runtime with over 350,000 GitHub stars, is now available in alpha for Windows running inside MXC. Microsoft warns that current profiles should not yet be treated as security boundaries, as the software remains in early preview.
The announcement positions Microsoft to capture enterprise AI agent deployment as companies move beyond demos to production systems that require security, auditing, and management capabilities.
Read more: Microsoft launches MXC, an OS-level sandbox for AI agents, with OpenAI and Nvidia already on board
