Update, October 8, 2026: New coverage: MAI-Code-1.1 Flash runs locally on Windows and Meta Muse is coming to Windows.
On October 7, 2026, Microsoft used a Windows and Surface event in San Francisco to describe a plan it calls hybrid intelligence: AI agents that run on your device when that makes sense and in the cloud when it does not, with Windows providing the security, identity and management layer around them. In its post, Building Windows for Hybrid Intelligence, the company positions Windows 11 as the place where agents live, not just a window for a chatbot.
This article explains what was announced, separates what shipped from what is still promised, and says what builders and IT teams should do. A caveat on sourcing: Microsoft's own post and several news sites were not reachable from our research environment, so the details below come from search summaries of the post and from coverage by Fortune, GeekWire and others. Where outlets disagree or we could not confirm a point, we say so.
TL;DR: the questions people are asking
| Question | Short answer |
|---|---|
| What is hybrid intelligence? | Routing AI work between local hardware and the cloud, per task |
| Is there a Windows 12? | No; this is Windows 11 plus agent and Copilot features |
| What shipped today? | Microsoft Execution Containers (MXC), reported generally available on Windows 11 |
| What is still coming? | Local Copilot features over the coming months; experimental dev-tool previews later in October |
| New hardware? | Surface Laptop Ultra (Nvidia RTX Spark) and a $5,999 Surface RTX Spark Dev Box, shipping November 2026 |
| Does local mean private? | Microsoft says so for its demo; verify per feature |
| Who supports MXC? | GitHub Copilot, OpenAI Codex and NVIDIA OpenShell, per reports |
| Do I need a new PC? | Not for MXC; local on-device models target Copilot+ PCs |
What "hybrid intelligence" actually means
The idea is a routing decision. Some tasks are small and private, such as sorting files, changing a setting or summarizing a local document. They can run on a model on your own machine, which saves cloud cost and keeps data local. Others, such as long reasoning or large coding jobs, need more compute than a laptop has, so they go to the cloud. Windows is meant to be the layer that lets software choose, and lets IT control the choice.
Press coverage of the event describes the same split. GeekWire reports Copilot can hand tasks to AI models running on the machine "when cost or privacy matter more." Fortune quotes Jacob Andreou, who leads Copilot, saying tasks that do not need heavy compute can run without touching the cloud. Satya Nadella is reported as saying that "just having the model doesn't do much for anything," arguing that local AI, AI-powered software and AI-native devices have to come together.
At Build in June, Pavan Davuluri, who runs Windows and Devices, framed the developer side as running workloads "on-device, in the cloud or across both without trade-offs." He has also said Windows will keep serving human users while adding agent workloads, with the work focused on low-level primitives for security, identity, governance, observability and performance rather than the user interface.
The part that shipped: Microsoft Execution Containers
The most concrete item is Microsoft Execution Containers (MXC). Reports on the October 7 announcement say MXC is now generally available on Windows 11. It gives organizations a way to set which files and networks an agent can reach, so an agent that misbehaves, or is tricked, is limited to what it was granted.
Reported supporters include GitHub Copilot, OpenAI's Codex and NVIDIA OpenShell. At Build in June, coverage described MXC as an early preview, so the move to general availability took about four months, if the reports are right. One of our searches could not confirm general availability, while a later round of event coverage and Microsoft's own post summary state it; treat the status as Microsoft's claim until you see it in the documentation.
Why this matters: agents that edit files, run commands and use a browser are the same class of tool where sandboxes have recently failed. See our coverage of agent sandbox isolation, the Vercel VM escape and Tencent's CubeSandbox. A container is a boundary, not a promise, so combine it with least privilege and review.
Agent identity and governance
Microsoft's framing also covers identity: reporting from Build says Windows can assign an agent a local identity or a cloud-provisioned one backed by Entra. The stated goals are to let organizations control what agents access, see which agent performed an action, and govern agents at scale. We could not confirm further detail, such as audit log formats or policy controls, and some third-party sites describe protocol names we could not corroborate, so we have left those out.
The part that is still future tense: local Copilot
According to event coverage, Copilot is getting permission-based access to local files and recent activity, the ability to take local actions, and on-device models on Copilot+ PCs. Reports say these features begin rolling out over the coming months, not with the hardware launch.
Keynote coverage described a few demos: Copilot building native Windows apps from a single prompt, and organizing files with local models, with the claim that sensitive information does not leave your machine in that case. Two cautions from commentators are worth keeping in mind. A demo does not confirm general availability. And it does not confirm that a feature runs locally on every device, or that it is included without a separate Microsoft 365 or Copilot license.
Also reported: experimental previews of the GitHub Copilot app, Copilot CLI and Visual Studio Code are scheduled for later in October. This is the clearest near-term date for developers.
The security issues around giving an assistant file access are not hypothetical. Our write-up of a Word document attack on Copilot and the guide to indirect prompt injection explain why permission prompts and containment matter as much as the model.
The hardware
The event pushed the Nvidia partnership.
| Product | What was reported |
|---|---|
| Surface Laptop Ultra | First Surface with Nvidia silicon (RTX Spark); up to 20 CPU cores, 6,144 GPU cores, up to 128 GB unified memory, about 1 petaflop of AI compute; 15 inch mini-LED display; Windows on Arm. Price not confirmed in the coverage we found; pre-event reports pointed to about $3,000, unverified |
| Surface RTX Spark Dev Box | $5,999, pre-order through Microsoft.com in the US, shipping November 2026 |
| DGX Station for Windows | GB300-based system for local token generation by agents, per Nvidia's product page |
| Partner RTX Spark PCs | From ASUS, Dell, Lenovo, HP and MSI, later in 2026 |
The Surface Laptop Ultra was first shown earlier in the year at Build or Computex, depending on the outlet, so the October event is a follow-up, not a debut. We have not tested any of this hardware.
If you are choosing between a Windows workstation and other local setups, our comparisons of MacBook versus dedicated GPU for local LLMs, the NVIDIA DGX Spark setup and the DGX Spark price and memory change show how much memory capacity and bandwidth decide what you can run. The Apple M6 Mac mini story covers the other camp, and Ghost Core shows the dedicated-box approach.
Jensen Huang's account of the partnership
After the event, NVIDIA CEO Jensen Huang posted on X, replying to Nadella's note thanking him and Sriram Krishnan for joining. Huang wrote that Windows "sparked a platform shift that created a new industry for NVIDIA," that NVIDIA then "invented programmable shading GPUs for DirectX, which led to CUDA," and that the two companies later partnered "to bring GPU supercomputers to Azure, which helped OpenAI train GPT." He tied that history to this week's work: "That collaboration inspired us to reinvent Windows for the age of personal agents." He added "4 years. Thousands of engineering years between us."
Nadella replied that he was grateful for "the deep partnership through all these shifts and now we're maybe on to the biggest."
Read this as a statement of position, not a product detail. It is a CEO recounting a shared history, and the causal chain (DirectX to CUDA to Azure to GPT to Windows agents) is Huang's own framing. It does tell you how NVIDIA sees the RTX Spark systems: as the third act of a Windows partnership, after gaming and datacenter. For specifics on what shipped, use the MXC and hardware sections above.
What is not confirmed
- The primary post. We did not read Microsoft's post directly. Details come from summaries.
- On-stage quotes. We found no reliable transcript of what Nadella or Jensen Huang said on stage, so we do not attribute remarks beyond those reported by Fortune and GeekWire. The Huang and Nadella quotes above come from their public X posts.
- A "HydraFusion" feature dated October 15. One live blog mentions it; we found no second source, so we have left it out.
- Surface Laptop Ultra pricing and ship date. Not confirmed in the coverage we found.
- Third-party "agent protocol" names. Some sites report specific names for Windows agent permissions that we could not corroborate.
What people are asking
Do I need a new PC to use this? MXC is a Windows 11 feature, so it should not require special hardware. Local on-device models in Copilot target Copilot+ PCs, which have neural processing units. Larger local models need serious memory and a strong GPU, which is what the RTX Spark systems are for.
Is this a bigger bet on agents than before? Yes. Microsoft is describing Windows as infrastructure for agents. Community reaction has been mixed, with some users pushing back on an "agentic OS" and asking for the basics to be fixed first. Treat the vision as a roadmap, and judge it by what ships and how controllable it is.
How does this relate to other coding agents? MXC support reported for Codex and GitHub Copilot suggests coding agents on Windows will run inside a managed boundary. See our guides to Codex computer use on Windows and the GitHub Copilot SDK.
What this means for what you build or run
- Test MXC now if you run agents on Windows. Define the folders and network hosts an agent needs, deny the rest, and see what breaks. Write the policy down.
- Design for routing. If you ship an app with AI features, plan for a local path and a cloud path, with a clear rule for which data may go where. Our closed-source versus local open-source guide covers the trade.
- Do not assume "local" means safe. A local model with file access can still be manipulated by hostile content. Keep human approval for destructive actions, as in our human-in-the-loop guide.
- Wait for documentation before rolling out. Features arriving "in the coming months" are plans. Ask Microsoft for the licensing, data-flow and admin-control details before you change policy.
- Watch the October previews. The experimental GitHub Copilot app, Copilot CLI and VS Code builds are the first real chance to see agent-on-Windows behavior.
Related reading on explainx.ai
- Agent sandbox isolation: five things to know
- Vercel KVM zero-day and agent sandboxes
- Codex computer use on Windows and mobile
- GitHub Copilot SDK for multi-platform agents
- NVIDIA DGX Spark: best local LLM setup
- MacBook vs dedicated GPU for local LLMs
- Ghost Core: the $3,499 on-device AI computer
- Microsoft Foundry naming explained
Details are based on Microsoft's October 7, 2026 announcement as summarized in news coverage, and may change as documentation is published. We did not read the primary post or test the products. Availability dates are Microsoft's stated plans.
