Microsoft has introduced the Microsoft Execution Containers (MXC) SDK as its strategy for securing AI agents on Windows and WSL. MXC provides a policy-driven execution layer with multiple isolation backends — process isolation, session isolation, planned micro-VMs, and Linux containers — configurable via JSON or a TypeScript SDK. IT teams can manage policies centrally through Entra ID and Intune, with Defender and Purview providing observability and audit trails. However, early commentary warns that MXC profiles should not yet be treated as security boundaries, with known issues including overly permissive policies and non-functional outbound network filtering. The piece also surveys the broader landscape: NVIDIA's OpenShell runtime, Red Hat's confidential containers with SELinux, Kubernetes-based agent sandboxes using gVisor and Kata Containers, and Linux-native approaches using cgroups, Landlock, seccomp, and eBPF. No single dominant platform security model for AI agents has emerged yet.

5m read timeFrom infoq.com
Post cover image
544 Impressions