Microsoft released Execution Containers, a containment layer for AI agents, to all Windows 11 developers on 7 October. Developers list the files and sites an agent may touch, and the agent cannot widen that list. GitHub Copilot and OpenAI's Codex already use it, and Microsoft says Claude Code will follow.