In brief: Microsoft has made Execution Containers (MXC) generally available on Windows and plans to let GitHub Copilot route between local and cloud models later in October. MXC can enforce file, network and UI boundaries outside the agent. Identity and Intune controls are still forthcoming, and local inference does not automatically make a session offline.
The security boundary sits outside the model
MXC can contain model output, tools, plugins or an entire agent. A policy defines readable and writable directories, allowed network destinations and UI access. Because it remains outside the workload, generated code cannot grant itself more permissions.
Lightweight process containers use AppContainer on Windows, Seatbelt on macOS and Bubblewrap on Linux. Windows 11 alone adds a session container with separate identity, desktop, clipboard and input. WSL containers support Linux toolchains; hardware-isolated microVMs remain experimental.
Only containment is generally available now. Microsoft describes Entra-based separation of user and agent activity and central Intune policy as “coming soon”. Calling Windows the most secure agent platform is therefore a vendor assessment, not an independent comparison of today's complete stack.
137 billion parameters locally, in a 53 GB model
For GitHub Copilot, Microsoft quantises MAI Code 1.1 Flash to roughly 3.3 bits per weight. The mixture-of-experts model has 137 billion total but 6.8 billion active parameters. Its local version occupies 53 GB, supports a 256,000-token context and peaks at 75.5 GB of memory at maximum context, according to Microsoft. The company recommends more than 120 GB of RAM for best performance.
Microsoft reports 70.8% on SWE-bench Verified and 66.29% on Terminal-Bench 2.1 for the quantised build. These are vendor results, not independent measurements. Terminal-Bench even exceeds the full-precision cloud model, but different runtime conditions and measurement variation prevent treating that as a general quality gain.
Pandorex Analysis
The key distinction is between inference and tool execution. A local model may still use cloud routing, networks or external tools; GitHub explicitly says local inference does not make a session offline. MXC limits those accesses but does not replace identity, auditing or data classification. Only routing, enforced permissions and the forthcoming management controls together can make local agents governable in enterprises.
