Microsoft has unveiled a new security layer for Windows designed to keep autonomous AI agents from wandering where they should not — alongside the most expensive Surface laptop it has ever sold. The software, called Microsoft Execution Containers, isolates AI agents on a PC and lets organizations control exactly which files and network resources an agent may touch.
The need is not theoretical. As agents gain access to files, accounts and code, a misread instruction or a malicious prompt can turn a helpful assistant into a liability; threat researchers have documented AI-assisted attacks compressing the time from initial compromise to data theft to as little as 25 minutes. Microsoft says its container approach shows administrators the reasoning behind security decisions rather than a bare risk score. Major AI developers and chip partners have signed on to adopt the technology.
The hardware half of the announcement is the Surface Laptop Ultra, the first laptop built on Nvidia’s RTX Spark chips, aimed at developers and creators who want to run AI models locally. Pricing starts at $2,599 with 24 GB of memory and reaches $5,899 for a 20-core configuration with 128 GB of memory and 1 TB of storage — well above the entry price of Apple’s competing pro laptop, reflecting how scarce and expensive AI-grade memory has become.
The event, held in San Francisco, also introduced an Nvidia-powered developer workstation. The strategic bet is clear: if agents are going to do real work on personal computers, the operating system — not the chatbot — has to be the security boundary.
Related reading: Atsign and Intel Say the Edge AI Encryption Bottleneck Is Broken With an 88x Speedup · CyberSentriq Launches SentriqAI to Bring Enterprise-Grade Defense to Small Firms · Starlink Mobile's Last Puzzle Piece: What Low-Band Spectrum Means for Your Phone