Microsoft's MXC SDK for containing AI agents remains in early preview at v0.8.0

Editorial illustration: A faceted metal machine with a jointed gripper arm sits inside a transparent blue-edged enclosure beside three glowing upright slabs on a dark platform.

In brief

  • Microsoft unveiled MXC at Build 2026 on June 2 to limit what AI agents can access.
  • Developers write MXC policies in JSON or TypeScript, and the OS kernel enforces them in real time.
  • MXC runs on Windows and WSL and binds agent actions to distinct identities.
  • MXC version 0.8.0, current as of September 2026, remains an early preview.

How the containment works

Developers don't have to manage low-level isolation themselves. According to Crypto Briefing's report, MXC abstracts that work away. Developers write access rules for specific resources as JSON or TypeScript policies, and the OS kernel enforces those rules in real time.

Microsoft calls the underlying structure a “composable sandbox.”

In practice, developers can mix and match how strong the isolation is. Each agent gets only the access it needs for the task at hand (a least-privilege model). MXC also binds agent actions to distinct identities, so there's a clear record of which agent did what when something goes wrong.

Why agents need it

Autonomous agents don't play by the rules that traditional security models assume. They generate code dynamically, the report noted. Microsoft specifically names unauthorized data access and UI spoofing among the risks MXC addresses.

That's the gap it's aimed at.

Partners and roadmap

GitHub Copilot is among the early adopters and has already put process isolation into its command line interface, Crypto Briefing reported. The same report lists OpenClaw (an open-source AI agent framework) and NVIDIA's OpenShell as early partners. Those partners give the project a foothold beyond Microsoft's own product family.

Microsoft isn't pitching MXC as a standalone product. The company positions it as a foundational primitive, a basic building block for other AI security tools. The roadmap points to tighter integration with Agent 365, Microsoft's platform for agents. MXC is also set to work alongside Entra, Defender, Intune and Purview, which make up the company's existing security and management lineup.

It's still early. Version 0.8.0, current as of September 2026, focuses on improvements to policy management and networking.

Frequently asked questions

What is Microsoft Execution Containers (MXC)?

MXC is a policy-driven SDK that Microsoft unveiled at Build 2026 on June 2, 2026. It's meant to stop AI agents from reaching data they shouldn't access by applying containment at the operating system level on Windows and WSL.

How does MXC enforce access rules for AI agents?

Developers write access rules for specific resources as JSON or TypeScript policies, and the OS kernel enforces them in real time. Each agent gets only the access it needs for its task. Agent actions are also bound to distinct identities, which creates a record of which agent did what.

Is MXC generally available yet?

No. According to Crypto Briefing, MXC is still an early preview. Version 0.8.0, current as of September 2026, focuses on policy management and networking improvements.