NVIDIA and Microsoft paired more powerful local AI hardware with tighter agent permissions at their October 7, 2026, event in San Francisco. RTX Spark laptop preorders opened, a larger Windows workstation was previewed, and Microsoft released Microsoft Execution Containers—software designed to keep an agent’s access within boundaries set outside the agent itself.
Portable AI versus deskside capacity
RTX Spark laptops are scheduled to become available October 16, with compact desktops following in November. NVIDIA lists systems from Acer, ASUS, Dell, HP, Lenovo, Microsoft, MSI and Gigabyte. The compact desktop design is intended for continuous operation, giving always-on agents a dedicated local machine.
DGX Station for Windows targets larger development workloads. NVIDIA says it can run models up to a trillion-parameter scale locally, but has not announced availability. Previously, DGX Station ran on Linux; the Windows version brings that computing environment onto the enterprise desktop, while retaining access to Linux tools through Windows Subsystem for Linux.
Two scales of local AI memory
01Up to 128GBRTX Spark
NVIDIA specifies up to 128GB of unified memory for its laptop and compact-desktop platform.
02748GBDGX Station for Windows
NVIDIA specifies 748GB of coherent memory for the previewed GB300 Grace Blackwell Ultra-based workstation.
More computing power, bounded authority
Microsoft Execution Containers, or MXC, addresses what agents are allowed to do rather than how much computing power they have. Developers specify permitted files, network destinations and other resources. MXC selects a container—a restricted execution environment—to enforce those permissions. The policy stays outside the workload’s control, so generated code cannot grant itself more access.
Microsoft illustrates the distinction with a coding agent updating a website. It could receive permission to edit the repository and read production configuration, without permission to change that configuration. The boundary is designed to block an unauthorized change even if the agent decides it would help finish the task.
- Process containers support Windows 11, macOS and Linux, providing lightweight containment for generated code and tool execution.
- Session containers are Windows 11-only, separating an agent’s desktop, clipboard and input from the person’s active session.
- Windows 365 support is also generally available, allowing agent workloads to run alongside existing work on Cloud PCs.
Observation is not enforcement
On Windows, MXC process containers can help developers discover which resources an agent needs. Learning mode blocks ungranted access and records attempts. Permissive mode records access that the policy would deny but lets it proceed, subject to other operating-system or organizational restrictions. Enforcement mode blocks unauthorized operations without producing the activity report.
Containment is available now; broader management is not all shipping yet. Microsoft says Entra-based attribution of agent activity, Agent 365 controls for local agents and Intune management policy for Windows 11 process containers are coming soon. Those additions are intended to let organizations govern agents separately from the employees using them.
Reader comments
Newest comments first. Replies stay oldest first.