From AI agent security and hybrid intelligence to Nvidia-powered Copilot+ PCs, here are five major takeaways from Microsoft’s Windows event.
Microsoft has moved its execution containers capability into general availability as part of a strategy to make Windows devices the most secure for artificial intelligence agents and agentic workloads, with plans to “soon” make Intune policies available for managing MXC process containers used by MXC-integrated agents on Windows 11.
The vendor will release Windows “hybrid intelligence” powered by its GitHub division’s HydraFusion task routing capability in an experimental preview this month.
One of the boldest proclamations from Microsoft’s Windows news event came not from Satya Nadella (pictured right), but from Nvidia founder, President and CEO Jensen Huang (pictured left) while sharing the stage with Microsoft’s chairman and CEO.
Huang called MXC and the architecture Microsoft showcased important to the next wave of application-building. This architecture is “the foundation of the next generation of IT as we know it,” Huang said. “MXC is going to revolutionize how agents are built and deployed. Without it, nonstarter.”
[RELATED: Logitech Expands Into Pro AV Market With Rally 2 Portfolio]
Peter Rodenhauser, president and CRO at Fort Wayne, Ind.-based Microsoft partner Corsica Technologies—No. 440 on the 2026 Solution Provider 500—told CRN in a recent interview that the solution provider has worked with midmarket clients around the increased volume of cyber incidents and preparing their organizations for quick reaction and restoration.
Corsica has also helped customers evaluate business objectives for AI tools, executing the plan and then seeing if the results delivered a return on the investment.
“These are organizations that rely very heavily on MSPs to educate them on what the power of some of these AI tools and capabilities are,” Rodenhauser said. “Also, how to not get too far out over your skis in terms of those capabilities.”
Microsoft’s Nadella said the vendor is making its Agent 365 AI agent control plane, Microsoft IQ intelligence layer and model system plus the Copilot AI virtual assistant the anchors to the new product portfolio.
“Today is the day we’ll start talking and thinking about the frontier ecosystem taking maybe slightly different contours in two years from now, five years from now, 10 years from now,” Nadella said.
In Nadella’s remarks during the event, the Microsoft CEO said that as the world enters year five of the AI era, “we have realized that just having a model doesn’t do much for anything” by itself. “You really do need to orchestrate it. You need to have memory outside of the model. You need to obviously have this harness layer that is able to take multiple models plus context plus memory and the action space, and really then prosecute the trajectory of the model’s output.”
Here’s more of what you need to know from the Microsoft Windows news event.

Microsoft Execution Containers Reach General Availability
At the heart of Microsoft’s architecture strategy for making Windows devices the safest for AI agent use are Microsoft Execution Containers, now in general availability on Windows 11.
The upcoming Intune capability can give IT administrators greater control over how Windows evaluates container creation requests made by agents, according to Microsoft.
MXC aims to allow organizations to define the files and networks AI agents can access with those policies enforced at runtime.
Agents will also have the ability to explain when a task can’t be completed due to available permissions as well as request an appropriate user or administrator action when supported. Agents can also choose safe alternatives.
The MXC open-source library is meant to translate policy into native operating system controls, according to Microsoft. MXC will mean users can leverage GitHub Copilot across Windows, macOS and Linux without needing separate virtual machines or container images, but Microsoft will make that an option through MXC in the future.
With MXC, developers can contain model-generated output, plug-ins, tools, agent harness or the entire agent, according to Microsoft. If something goes wrong, the impact scope is limited.
Policies stay outside the agent workload’s control, preventing the agent or generated code from granting itself additional access—a concern likely on users’ minds with the multiple publicly disclosed rogue agent hacks.
Developers integrate with a unified JSON configuration schema and multi-language SDK, and MXC maps the requested controls to the selected back ends on Windows, macOS or Linux, creating a simpler experience by separating workload requirements from platform-specific containment details, according to Microsoft.
Developers can apply the same containment model for a local device, the cloud and wherever else an agent needs to run.
Agents supporting MXC include OpenAI’s Codex, Microsoft’s GitHub Copilot, OpenClaw, Replit, Element Labs’ LM Studio, Nvidia’s OpenShell and Unsloth AI.
Upcoming support is expected from Anthropic Claude Code, Box, Egnyte, Heidi Health, Nous Research’s Hermes Agent, Manus, Perplexity, Raycast and Simular and others.

Copilot, Search Upgrades, HydraFusion Access
Following on the news from September that Microsoft is rebuilding the Copilot experience, Microsoft executives said Wednesday that Copilot on Copilot+ PCs will offer users more power through Windows hybrid intelligence.
Microsoft expects to start rolling out Copilot hybrid intelligence features “in the coming months,” according to the vendor.
Through hybrid intelligence, Copilot can leverage local context, files and recent activity from the user’s PC. Copilot can organize files, assess device diagnostics, troubleshoot issues, code, carry out workflows and perform other tasks locally for users with their permission.
Copilot can also access local AI models running on the PC, using local compute for certain tasks and tapping into the cloud when it must, according to Microsoft.
Microsoft has started rolling out new Windows Search capabilities to members of its Windows Insider program in the experimental channel and plans to introduce an opt-in Copilot and Search integration to select markets later this year.
The goal is for a Search with better performance, speed and memory usage, according to Microsoft. The UI is now in a single list for quicker scanning. Search should better understand what users are looking for through better typo and synonym matching, which Microsoft will fine-tune “over the coming weeks.”
Another major announcement Wednesday was expanding access to the HydraFusion capability made by Microsoft’s GitHub division.
The capability can help users save on token consumption, according to Microsoft. The vendor will release HydraFusion-powered Windows hybrid intelligence in an experimental preview this month.

New RTX Spark-Powered Copilot+ PCs Arrive
Microsoft has opened preorders for new Copilot+ PCs hitting the market powered by Nvidia’s RTX Spark. Surface Laptop Ultra and third-party PCs in this cohort start shipping Oct. 16.
Users can also preorder the Surface RTX Spark Dev Box aimed at developers and AI engineers who evaluate AI models, iterate locally and need local AI compute. The Dev Box will ship to U.S. customers starting in November.
The Dev Box will ship with Project Zenith, a ready-to-code Windows experience, pre-configured out of the box.
Microsoft bills the Surface Laptop Ultra as its most powerful Surface device with 128 GB of unified memory and the ability to run AI models exceeding 120 billion parameters locally.
The Ultra has about three times the thermal capacity for existing laptops to help with speed under sustained loads and to avoid sacrificing performance when unplugged on battery. It can maintain more than 99 percent of its power while on battery power.
The laptop measures less than 0.7 inches thin and less than 4.5 pounds. Microsoft boasts of Ultra having the brightest peak HDR of any laptop and the most ports on a Surface Laptop. The laptop has a magnetic connect for built-in magnetic charging without sacrificing the USB-C port.

Microsoft Partners Roll Out New AI PCs
Breaking down the PCs made by Microsoft device partners that also start shipping Oct. 16, Dell Technologies positions its XPS 16 Creator Edition (pictured) as giving creators and developers studio-grade performance, professional display accuracy and local AI development on the go.
The HP OmniBook Ultra 16 promises users an ultrathin design that delivers sustained performance during demanding AI workloads thanks to its thermal capabilities.
Lenovo’s Yoga 9n 2-in-1 device offers a 360-degree design and dual-surface pen input for creators.
Asus will offer a ProArt P16 and ASUS ProArt P14 that measure 16 and 14 inches, respectively. The devices have Asus’ Lumina Pro OLED displays and big capacity battery life, according to Microsoft.
And the Prestige N16 Flip AI+ 2-in-1 by Micro-Star International offers a 16-inch ultra-high-definition plus Tandem OLED display and a 99.9 watt-hours battery.
Microsoft said that devices will use 3-bit precision to reduce the model size of its Microsoft AI Code 1.1 Flash model by about 80 percent. The reduced Code 1.1 Flash still promises coding quality and support for a 256K context window locally.

DGX Station Systems Bring Frontier AI Workloads Local
Later this year, the Dell Pro Precision with GB300 and HP ZGX Fury AI Station will make up part of the Windows devices built with Nvidia’s DGX Station that promise to enable frontier-class models and agentic workloads on devices instead of just through the cloud or data centers.
Microsoft bills these devices as bringing users last quarter’s frontier capabilities and the RTX Spark devices as bringing last year’s frontier capabilities. Users will have access to powerful capabilities in a deskside computer without needing to rent a cluster.
These DGX Station devices will leverage Nvidia’s GB300 Grace Blackwell Ultra Desktop Superchip and deliver data-center-class performance with enterprise-grade security, according to Microsoft.
The devices should have the ability to run Llama 4 Maverick, Kimi K2.6, DeepSeek V4 Pro and other frontier-class AI models locally at more than 1 trillion parameters, according to Microsoft.
DGX Station for Windows users will have the ability to run the most demanding engineering, scientific and research workloads and accelerate Windows apps through multimodal agents that can model, perceive and design for the real world.
Users can also leverage these devices as scalable token factories that support 32 or more simultaneous agents as a way to cut down on cloud token consumption.
Local inferencing also allows users to keep sensitive data and IP inside their environments and manage the devices through Windows fleet management tools they already use.





