Copilot will get access to files and the ability to take actions in Windows: what a company should check before letting an AI assistant onto its computers
Topics: AI, Security, Small business

Short answer: on October 7, 2026, at its Windows and Surface event, Microsoft showed an update to Copilot that will give it access to files on the computer and the ability to take actions in the system. In the demo, the assistant, from a single request, found the necessary documents in different folders, renamed them, put them in an archive and prepared an email to an accountant with that archive. Microsoft promises these features over the next couple of months. On the same day, the company announced the general availability of Microsoft Execution Containers, a mechanism that limits which files and network addresses an AI agent can access. Microsoft itself writes that an agent cannot be its own security authority. For a small company, this leads to six measures before turning on such an assistant: separate folders and a separate account, drafts only at first, emails and messages sent only by a person, a backup, a way to tell the agent's actions from an employee's, and cost control. Below is what was announced, how Microsoft proposes to limit agents, these measures, and a calculation of when the time saved outweighs the time spent checking.
What Microsoft showed
An AI agent is a program built on a language model that carries out steps towards a goal by itself: it searches for files, opens programs, writes emails. A person sets the task, and the agent decides how to carry it out.
According to The Verge, at the event on October 7, 2026, Jacob Andreou, the head of Copilot, showed a video. He told the Autopilot assistant that he had received an email from his accountant and asked it to get her everything she needed. The assistant found the documents in different folders, renamed the files, put them in an archive and prepared a draft email to the accountant with that archive. Microsoft calls the approach Hybrid Intelligence: programs use a mix of models running on the computer itself and models in the cloud. Features based on it, Andreou said, will come to Copilot "over the next couple months".
Two more announcements from the same day:
- Windows search with actions. From the search bar, you will be able to turn on dark mode, change the microphone volume or send a message. According to Windows and Surface head Pavan Davuluri, this will come to Windows 11 PCs starting this fall.
- Microsoft Execution Containers (MXC). A mechanism that keeps an agent within set limits. More on it below.
Microsoft introduced this assistant under the name Autopilot earlier, on September 25, 2026, in a blog post about the new Copilot; before that it was called Scout. It is an assistant that runs in the cloud, can carry out tasks on a schedule and keep working while you are away from the computer. As Microsoft describes it, it has its own account, memory and workspace inside the organization, backed by permissions, an activity log and governance rules. As of September 25, Microsoft planned a private preview of Autopilot at the end of September. Long-running agent work in the new Copilot is billed by actual usage, separately from the regular subscription.
How Microsoft itself proposes to limit agents
For a company, the most useful part of the October 7 announcements is not the demo but a post on the Windows developer blog about MXC. Microsoft describes the choice companies face: give agents unrestricted access and hope nothing goes wrong, or block them and lose the benefits. The company considers neither option acceptable.
The main idea of the post: an agent cannot guard itself. The limits are set by the developer or the organization and enforced by the system independently of the agent. Microsoft gives an example. An agent is asked to update a company website. It needs to read and change the website code, and it may read the production server's settings but must not change them. Without an external boundary, the agent may decide that changing the server settings is the fastest way and break the live website. From its point of view, the step is reasonable, but it was never given that right.
What MXC does, as Microsoft describes it:
- A list of what is allowed. For the agent, you list in advance the folders it may change, the folders it may only read, network addresses and access to the desktop. In enforcement mode and in learning mode, everything not on the list is closed (the modes are described below). The agent cannot expand its own rights.
- Levels of isolation. From a lightweight sandbox for a single process, to running the agent under a separate Windows account with its own desktop and clipboard, to experimental hardware-level isolation.
- Three modes. In permissive mode, actions outside the list are allowed but recorded in a report. In learning mode, they are blocked and recorded. In enforcement mode, they are simply blocked. This lets you set permissions based on facts rather than guesswork. Microsoft describes permissive mode as a way to gather information while drawing up the list of permissions. In my view, on a computer with work documents it should be treated not as a trial run but as working without restrictions: actions outside the list go through in it.
Microsoft writes that MXC is already supported by GitHub Copilot, OpenAI Codex and several other agents, and that others are preparing support. The company also promises that Windows will soon allow its identity service, Microsoft Entra, to distinguish an agent's actions from an employee's in Microsoft Agent 365, its agent management system, that is, within Microsoft's corporate product stack. This is primarily a tool for developers and administrators, but the principles themselves also work for a company without an IT department.
Six measures before turning on an assistant with access to files
Applying Microsoft's principles to a small company is my own step. The measures suit both Copilot and other agents that are given access to a computer.
- Give the agent only the folders it needs. Put the documents it will work with into separate folders. Run the agent under a separate Windows account that has access only to these folders, and set up this access in Windows itself. A list of folders in the agent's own settings does not replace such protection: it is enforced by the agent itself, and Microsoft, as mentioned above, writes that an agent cannot be its own security authority. If a separate account cannot be set up, assume the agent can access everything the employee under whose account it runs can access. In that case, either give it a separate computer or account that holds only the necessary folders, or do not give it access to files. Keep folders with contracts, HR documents and customer data closed until you decide the agent needs them. Before opening customer data to the agent, read the assistant provider's data processing terms separately.
- Who does it: whoever sets up the computers, an employee or a contractor; the owner approves the list of folders.
- How to check: ask the running agent itself to open several folders outside the list, including folders with contracts and HR documents, and make sure it gets an access denied error from Windows. A manual check under the agent's account does not work: it does not show what rights the assistant itself runs with. If such a check cannot be done, the measure is not met.
- Start with drafts. For the first one or two weeks, the agent only prepares things, without changing or sending anything: draft emails, a list of found files, a proposal for renaming. A person looks at what it would have done and compares it with their own decision.
- Who does it: the employee who currently does this work.
- How to check: there is a written list of differences between what the agent proposed and what a person would have done. This is not the same as MXC's permissive mode: here the agent has no right to act.
- Emails, messages, publications and payments are sent by a person. The agent prepares a draft, a person sends it. In Microsoft's demo, the assistant also prepared a draft email.
- Who does it: the employee responsible for the area; whoever sets up the agent configures its rights.
- How to check: on a test copy without work data, every sending channel you have is checked in turn: email, messengers, publishing on a website or social media, payment. Every attempt by the agent to send ends in a refusal, while it can create a draft.
- The limit of this measure: it covers only these sending channels. If the agent has network access, data can leave through allowed addresses, including through the assistant service itself: this is how such assistants work, and the check above does not rule it out. So the rule for the first measure is: put into the agent's folders only what you are ready to give to any recipient the agent can reach, that is, the assistant provider and every allowed address. Keep the list of allowed addresses short and written down, include only addresses without which the task cannot be done (in MXC, network addresses are part of the allowed list), and review it whenever you give the agent a new task.
- Make a backup before granting rights to change files. In the demo, the agent renamed files. If it is allowed to change or move files, a mistake will change real documents.
- Who does it: whoever is responsible for the computers and file storage.
- How to check: you have restored a folder from the backup once on a test computer and opened several files.
- Be able to tell the agent's actions from an employee's. Microsoft promises this capability for its corporate products (Entra and Agent 365). Until it is available, or if you do not use them, the agent's separate account from the first measure and its activity log help.
- Who does it: whoever sets up the agent.
- How to check: from yesterday's log, you can say which changes to files were made by the agent and which by a person.
- Control costs. Long-running agent work in Copilot is billed by usage, and Microsoft has released separate cost-control tools for this. Check in your plan's settings which limits are available on it.
- Who does it: the owner or whoever manages the budget.
- How to check: you know which spending limits your plan has and what happens when they are reached. If there is no hard limit, someone checks actual spending once a week and compares it with what was expected.
Six more rules for a company that gives tasks to an AI agent are in my article When an AI agent bends the rules: three cases from 2026 and six rules for a company.
Will the time spent checking pay off
An example with made-up numbers; substitute your own. An accountant or manager gathers documents on request 15 times a week: finds the files, renames them, puts them in an archive, writes an email. By hand, this takes 12 minutes per request, 180 minutes a week. The agent does the same, and a person checks the archive and the email before sending in 3 minutes: 45 minutes a week. The saving is 135 minutes a week, 9 hours over four weeks. At an employee cost of 1,000 rubles an hour, that is 9,000 rubles a month, from which you need to subtract the cost of the assistant itself and the setup time.
The calculation depends heavily on the time spent checking. If checking takes 8 minutes, the saving drops to 60 minutes a week, 4 hours a month. At 12 minutes, checking takes as long as doing the work by hand, and the assistant saves no time on this task.
What about availability
Microsoft's support page says that Copilot is available in more than 170 markets, with exceptions for China (excluding Hong Kong) and embargoed markets, where it is not available or not supported. Separately, Microsoft writes that new features may not appear in all regions and languages at once. Whether a specific feature works for your company, check on your own computers and with whoever sells you licences. The principles in this article do not depend on this: they work for any agent with access to files.
When these measures are excessive
If the assistant only answers in a chat window and sees no files, no email and no other programs, most of the measures against the agent's independent actions are not needed. Two things remain: checking the answers on their merits, and agreeing on what employees paste into the chat and what they do not, for example contracts, customer data and passwords. The measures become necessary when the assistant gets the right to read, change or send something on your behalf, and the more such rights it has, the more measures are worth turning on.
Summary
On October 7, 2026, Microsoft showed a Copilot that finds documents in folders, renames them, puts them in an archive and prepares an email by itself, and promised such features over the next couple of months. On the same day, the company made generally available a mechanism that keeps agents within set limits, and wrote plainly that an agent cannot guard itself. For a small company, this leads to a simple sequence: separate folders and a separate account for the agent, drafts only at first, emails and messages sent by a person, a backup, a log and cost control. And the benefit should be calculated with the checking time included: if checking takes as long as doing the work by hand, the assistant is not needed for that task.
I work on AI agents and automation. If you would like to see my projects or discuss your own task, take a look at my portfolio.
Sources
- The Verge, 07.10.2026: Microsoft is giving Copilot more control over Windows and your files. https://www.theverge.com/tech/1007113/microsoft-windows-copilot-ai-control-search-hybrid-intelligence
- Ars Technica, 08.10.2026: Microsoft event debuts new AI-friendly hardware and Windows changes. https://arstechnica.com/gadgets/2026/10/microsoft-event-debuts-new-ai-friendly-hardware-and-windows-changes/
- Windows Developer Blog, 07.10.2026: Microsoft Execution Containers: policy-driven containment for AI agents. https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-driven-containment-for-ai-agents/
- Official Microsoft Blog, 25.09.2026: Introducing the new Copilot with Home, Code and Autopilot. https://blogs.microsoft.com/blog/2026/09/25/introducing-the-new-copilot-with-home-code-and-autopilot/
- Microsoft Support: Supported regions and languages in Microsoft Copilot (opened 08.10.2026). https://support.microsoft.com/en-us/topic/26de43a1-c176-4908-bef7-29c8c37ac7ce