Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft says its new Microsoft Execution Containers (MXC) can restrict an AI agent to specified files and network destinations, blocking attempts to access resources outside that policy. Announced as generally available on October 7, 2026, MXC is a way to limit an agent’s reach—not a guarantee that it can never delete a file. If deletion is allowed within the resources granted to a workload, the policy alone does not make that action safe.

What Microsoft Execution Containers do

MXC is a policy-driven containment layer for untrusted code and dynamically generated workloads, including agents, plugins, tools, or an agent’s harness. A developer or IT administrator specifies the resources a workload needs; MXC maps those requirements to a container backend on Windows, macOS, or Linux and enforces the resulting boundary at runtime. The policy stays outside the workload’s control. Microsoft’s announcement is available in its Windows Developer Blog.

That distinction matters: the guardrail is not the agent deciding to behave. Microsoft Corporate Vice President Logan Iyer put the principle this way: “An agent cannot be its own security authority.” Under the design Microsoft describes, a model, generated code, plugin, or tool cannot override the containment boundary simply by attempting a prohibited action.

What the file protection does—and does not—cover

Example: read configuration, but do not change it

Microsoft’s example is a coding agent that can read and write a website repository and read production-server configuration, but is not authorized to modify that configuration. A policy can give the workload different access to those resources, allowing the permitted repository work while denying an attempted write to the protected configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
GMKtec AI Mini PC Ryzen Al Max+ 395 (up to 5.1GHz) Mini Gaming Computers
  • EVOLUTION AMD RYZEN AI MAX+ 395 MINI PC - GMKtec EVO-X2 is the next evolution in AI mini PC Ryzen Strix Halo series. Thanks to AMD Simultaneous Multithreading (SMT) the core-count is effectively doubled, to 32 threads. Ryzen AI Max+ 395 has 64 MB of L3 cache and can boost up to 5.1 GHz, depending on the workload. The Ryzen AI Max+ 395 is currently rated as the "most powerful x86 APU" on the market for AI computing.
  • AI NPU with XDNA 2 ARCHITECTURE - Powered by 16 “Zen 5” CPU cores, 50+ peak AI TOPS XDNA 2 NPU and a truly massive integrated GPU driven by 40 AMD RDNA 3.5 CUs, the Ryzen AI MAX+ 395 is a transformative upgrade and delivers a significant performance boost over the competition. The Ryzen AI Max+ 395 excels in consumer AI workloads like the llama.cpp-powered application: LM Studio. Shaping up to be the must-have app for client LLM workloads, LM Studio allows users to locally run the latest language model without any technical knowledge required and unleash their creativity and productivity.
  • AMD RADEON 8090S iGPU GAMING PC - The AMD Radeon RX 8060S offers all 40 CUs with up to 2.9 GHz graphics clock and uses the new RDNA 3.5 architecture. The powerful iGPU is positioned between an RTX 4060 and 4070 laptop GPU and therefore enables gaming in FHD at maximum details in most demanding games. The 8060S can also utilize the full 128GB pool, which is perfect for running LLMs such as Deepseek 70B Q8, which runs comfortably on this machine.
  • EIGHT CHANNEL LPDDR5X - LPDDR5X is a new ground breaking memory small form factor installed on-board. With blazing speeds up to to 8000MT/s, it runs 1.5x faster than the DDR5 SODIMMs; 90% better performance over DDR5 SODIMMs in video conferencing and photo editing; 30% better performance in productivity apps; 12% better performance in digital content workloads.
  • QUAD SCREEN 8K DISPLAY SUPPORT - EVO-X2 AI Mini PC support 4-screen 4K/8K output via HDMI 2.1 (8K@60Hz), DisplayPort 1.4 (4K@60Hz), and dual USB 4 40Gbps Transfer speed (supporting PD3.0/DP1.4/DATA). Ideal for gaming, video editing, and multitasking, it provides expansive and crisp multi-display support.

The policy defines the limit

MXC can block access beyond the resources authorized for a workload. It does not establish a universal “no accidental deletion” guarantee: if the policy grants write access to a file or directory, the containment boundary is not, by itself, a human approval step for every change. Developers still need to decide which paths and destinations are appropriate to grant.

Microsoft’s October announcement describes the architecture and example, but does not publish a statistic showing how much MXC reduces accidental deletion or other harmful outcomes. The announcement therefore supports a claim about how access is constrained, not a quantified claim about real-world effectiveness.

Rank #2
AMD Ryzen™ AI Halo - Personal AI Desktop Computer - Developer Platform - Linux OS
  • Built for Local AI Development: AMD Ryzen AI Halo is designed for local AI development and inference, featuring 128GB unified memory and support for up to 200B parameter models to build and run intensive AI workloads locally.
  • 128GB Unified Memory: Features 128GB LPDDR5x unified memory at 8000 MT/s with 256 GB/s memory bandwidth, providing a shared memory pool across the CPU, GPU, and NPU to support larger AI models.
  • AMD Ryzen AI Max+ 395 Processor: Features 16 cores, 32 threads, and Zen 5 architecture, paired with AMD Radeon 8060S integrated graphics featuring 40 RDNA 3.5 compute units and an AMD XDNA 2 NPU with up to 50 TOPS.
  • Linux AI Developer Platform: Purpose-built for Linux-based AI development with full AMD ROCm software support and preloaded tools, models, and workflows optimized for local AI development.
  • Compact, Connected Design: Includes a 2TB M.2 SSD, 10GbE LAN, Wi-Fi 7, Bluetooth 5.4, USB-C connectivity, and HDMI 2.1b.

How MXC differs from other agent safeguards

Control What it scopes or enforces Who controls the boundary Availability described by Microsoft
Microsoft Execution Containers Workload access to declared resources such as files and network destinations; runtime enforcement through a container backend. Developers or IT administrators define policy outside the workload. Generally available, as stated in Microsoft’s October 7, 2026 announcement.
Process and session isolation Process isolation targets lightweight, responsive work such as coding-agent execution. Session isolation separates an agent from a person’s desktop, clipboard, input devices, and active session; Microsoft also describes distinct identities, auditability, and filesystem policies. Isolation and filesystem policies are part of the platform security design. Microsoft’s June 2, 2026 post described the MXC SDK as an early preview. That post is a separate, earlier rollout statement, not the October general-availability announcement. See Windows platform security for AI agents.
Tool approval and path checks Approval gates pause sensitive or consequential tool calls; path checks verify that a requested file remains within allowed directories. Developers implement these safeguards in the agent or application. Documented as developer guidance, not as safeguards MXC automatically enables for every agent. See Microsoft’s Agent Safety guidance.
VS Code OS-level sandboxing Sandboxing applies to terminal commands and child processes; other built-in tools are governed separately. Outbound network access is not blocked by default. VS Code’s sandbox governs the covered processes, with separate controls for other tools. Product-specific behavior described in Microsoft’s VS Code agent trust and safety documentation.
Windows Copilot Actions controls Microsoft describes distinct agent accounts, limited privileges, an agent workspace, and user visibility and control. Windows security controls and user oversight. The page describes an experimental feature planned for Windows Insiders in Copilot Labs—not the same feature or rollout milestone as MXC. See Securing AI agents on Windows.

These controls operate at different layers. A runtime container can constrain a workload’s resource access; an OS sandbox may cover only certain processes; and an approval gate can require a person to authorize a particular tool call. One should not be assumed to provide the coverage of another.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What developers should still do to reduce risky changes

Microsoft’s Agent Framework guidance says tools run without user approval by default. It recommends approval gates for side-effecting, sensitive, irreversible, or broad-impact operations; deletion is riskier than a read-only query. It also recommends resolving file paths and checking that they remain within allowed directories.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GMKtec EVO-X2 AI Mini PC Ryzen Al Max+ 395 Superchip 128GB LPDDR5X 2TB SSD
  • EVOLUTION RYZEN AI MAX+ 395 MINI PC - GMKtec EVO-X2 is the next evolution in AI mini PC Ryzen Strix Halo series. Thanks to AMD Simultaneous Multithreading (SMT) the core-count is effectively doubled, to 32 threads. Ryzen AI Max+ 395 has 64 MB of L3 cache and can boost up to 5.1 GHz, depending on the workload. The Ryzen AI Max+ 395 is currently rated as the "most powerful x86 APU" on the market for AI computing.
  • AI NPU with XDNA 2 ARCHITECTURE - Powered by 16 “Zen 5” CPU cores, 50+ peak AI TOPS XDNA 2 NPU and a truly massive integrated GPU driven by 40 AMD RDNA 3.5 CUs, the Ryzen AI MAX+ 395 is a transformative upgrade and delivers a significant performance boost over the competition. The Ryzen AI Max+ 395 excels in consumer AI workloads like the llama.cpp-powered application: LM Studio. Shaping up to be the must-have app for client LLM workloads, LM Studio allows users to locally run the latest language model without any technical knowledge required and unleash their creativity and productivity.
  • AMD RADEON 8090S iGPU GAMING PC - The AMD Radeon RX 8060S offers all 40 CUs with up to 2.9 GHz graphics clock and uses the new RDNA 3.5 architecture. The powerful iGPU is positioned between an RTX 4060 and 4070 laptop GPU and therefore enables gaming in FHD at maximum details in most demanding games. The 8060S can also utilize the full 128GB pool, which is perfect for running LLMs such as Deepseek 70B Q8, which runs comfortably on this machine.
  • EIGHT CHANNEL LPDDR5X - LPDDR5X is a new ground breaking memory small form factor installed on-board. With blazing speeds up to to 8000MT/s, it runs 1.5x faster than the DDR5 SODIMMs; 90% better performance over DDR5 SODIMMs in video conferencing and photo editing; 30% better performance in productivity apps; 12% better performance in digital content workloads.
  • QUAD SCREEN 8K DISPLAY SUPPORT - EVO-X2 AI Mini PC support 4-screen 4K/8K output via HDMI 2.1 (8K@60Hz), DisplayPort 1.4 (4K@60Hz), and dual USB 4 40Gbps Transfer speed (supporting PD3.0/DP1.4/DATA). Ideal for gaming, video editing, and multitasking, it provides expansive and crisp multi-display support.
  • Grant an agent access only to the files and network destinations it needs; avoid giving write access to resources it only needs to read.
  • Use an explicit path allow-list and verify resolved paths stay inside the allowed directories.
  • Require human approval for deletion and other high-impact or irreversible operations when the application needs that safeguard.
  • Check the scope of each sandbox or isolation mechanism: for example, VS Code’s documented sandbox does not block outbound network access by default, and other built-in tools are handled separately.

These are complementary implementation practices, not evidence that MXC automatically applies every safeguard to every agent. The specific policy and the tools an application exposes determine what is restricted and what still requires approval.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.