Site navigation

Windows 11 Agentic AI Comes With Major Security Caveats

Graham Turner

,

Windows 11 AI
Microsoft has acknowleged that the technology could enable data exfiltration, unintended actions and even malware installation.

Microsoft has issued a detailed security warning (that they’ve packaged as ‘features’) about its upcoming “agentic AI” in Windows 11, cautioning users that the technology could expose devices to risks including data exfiltration and malware installation.

The company is preparing to roll out new AI agents capable of completing tasks and interacting with apps and files on a user’s behalf, but says the feature will remain switched off by default due to the potential dangers.

The shift forms part of Microsoft’s broader push to make Windows 11 a fully AI-powered operating system.

The company has been teasing its agentic OS ambitions for months, promising capabilities where AI can “click, type and scroll like a human would”, enabling automated actions and background task-completion. The first experimental versions of these agents are already available to Windows Insiders through Copilot Labs, with further features arriving gradually.

But in an extensive warning published across its support materials and developer documentation, Microsoft stresses that these agents introduce new and significant security considerations.

According to Microsoft, agentic AI will operate through “agent accounts” created locally on the device. Each agent runs in its own workspace with its own account, separate from the user’s, and can request access to known folders such as Documents, Downloads, Desktop, Music, Pictures and Videos. While the company says all actions must be human-approved and logged, the warning also highlights the risks associated with allowing AI-powered apps to interact autonomously with files and interfaces.

In Microsoft’s own words, agentic applications introduce “novel security risks, such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation.”

The company further notes that AI agents “still face functional limitations” and “may hallucinate and produce unexpected outputs”, increasing the possibility of unintended behaviour. Because of this, Microsoft states that the setting “can only be enabled by an administrator user” and warns users to “only enable this feature if you understand the security implications”.

Once activated, the agentic feature is enabled system-wide for all users, including other administrators and standard accounts.

Microsoft explains that agent workspaces run in a dedicated Windows session, providing isolation from the user’s desktop while still enabling agents to interact with apps in parallel. These workspaces are designed to scale their CPU and memory usage based on activity, with Microsoft planning to introduce different types of agent workspaces over time.

The company outlines a set of design and security principles governing Windows’ agentic future. These include requiring visibility and non-repudiation for all agent actions, ensuring agents only access data in “clearly defined” and user-authorised contexts, and restricting privileges using granular, time-bound permissions.

Microsoft also emphasises the need for supervised decisions, insisting that “users should be able to review the steps and approve the plan and monitor the execution of the plan.”

Agents “must be able to produce logs outlining their activities” and Windows must be able to verify these actions using a “tamper-evident audit log.” Microsoft also notes that agents are autonomous software entities that must be “contained”, and stresses alignment with the Microsoft Privacy Statement and Responsible AI Standard.


Recommended reading


In addition to security warnings, Microsoft has published a list of known issues for early builds, including devices failing to sleep while Copilot Actions are active, shutdown warnings suggesting another user is logged in, and leftover Intune-managed profiles not being cleaned up. Microsoft says fixes are in progress.

Although the features remain experimental and off by default, Microsoft frames the work as a foundational step towards enabling “intelligent, agent-powered computing” across Windows.

The company says security is a “continuous commitment” that will evolve alongside the rollout of agentic capabilities from developer previews to general availability.

For now, users must explicitly opt in and if you want to be on the bleeding edge, fair play – but know that it comes with some pretty big risks.

Join the Conversation

Don’t miss DIGIT Expo 2025 on 27 November at the EICC Edinburgh – Scotland’s largest tech showcase featuring 5 stages of keynotes, 60+ exhibitors and networking with 1,700+ IT & digital professionals.

Secure your free ticket now: Register here

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data