AI News · Models ·
Microsoft unveils local AI coding model and agent access security

Microsoft unveiled an AI coding model that can run directly on personal computers, according to October 8 coverage. It also introduced security technology intended to prevent AI agents from accessing data without permission. The announcements included models previously requiring cloud access that can now run on high-powered Windows desktops and laptops, including Nvidia's open-source Nemotron model.
Key points
- Microsoft unveiled a locally running AI coding model and security controls for agents on Windows PCs.
- Microsoft Execution Containers lets IT departments set agent rules that Windows enforces on employee machines.
- Davuluri said a version of DeepSeek’s V4 model requires at least 60 gigabytes of memory.
- The Surface Laptop Ultra starts at $2,599, with a higher configuration priced at $5,899.
- Copilot will split work between local models and cloud services, keeping the hardest tasks in the cloud.
What happened: Microsoft unveiled an AI coding model that runs directly on personal computers and security technology intended to stop AI agents from accessing data or performing tasks without permission. Reuters reported the announcements in October 8 coverage of Microsoft’s San Francisco event. The company is trying to make Windows a platform for agents that write code and tackle complex business projects on desktops and laptops, challenging Apple’s efforts to bring more AI processing onto personal devices.
The details: Microsoft said models that previously required cloud access can now run on high-powered Windows machines, including Nvidia’s open-source Nemotron model. Pavan Davuluri, Microsoft’s executive vice president for Windows and devices, said a version of DeepSeek’s V4 model can run on computers with at least 60 gigabytes of memory and outperform OpenAI’s GPT-5 on some coding and reasoning tasks. Detailed benchmark results were not reported. Microsoft is also dividing work between cloud services and local computers through Copilot, its AI assistant. Copilot chief Jacob Andreou said the hardest tasks would still use the cloud, while tasks where cost or privacy matter more could go to local models.
The details: The security technology, called Microsoft Execution Containers, or MXC, is designed to restrict what agents can access and do on a computer. Davuluri said IT departments would be able to set rules that Windows would enforce on each employee’s machine. He said Anthropic, OpenAI and Nvidia would use the tools. Meta’s Muse personal assistant will also come to Windows as a native app using some of the security tools, while the open-source OpenClaw agent system can work with them. Detailed configuration requirements and independent assessments of the controls were not reported.
Who it affects: For businesses, the announcements connect two practical questions: whether employee computers can handle AI workloads and how IT teams can constrain autonomous software. Microsoft’s strategy would shift some processing from its Azure cloud data centers to machines whose hardware costs are borne by customers, Reuters reported. But local execution requires capable hardware. Microsoft introduced a Surface Laptop Ultra powered by Nvidia’s RTX Spark chips, starting at $2,599. A configuration with a 20-core processor, 128 gigabytes of memory and one terabyte of storage will cost $5,899.
What to watch: Hardware prices could limit adoption. Reuters reported that a memory-chip crunch had raised device costs, complicating the case for running AI locally to save money. For teams evaluating the announcements, the immediate considerations are hardware requirements and how permission restrictions work in their own environments. The 60-gigabyte memory requirement cited for DeepSeek’s V4 version is above the entry-level Ultra’s 24 gigabytes. Local AI also does not mean abandoning cloud services: Microsoft explicitly plans to keep Copilot’s hardest tasks in the cloud.
Our take
Local execution and permission controls address two practical barriers to enterprise agents. Teams should assess hardware requirements and verify how access restrictions work in their own environments.