AI

Copilot Gets Control of Windows and Your Files as Microsoft’s Recall Bill Comes Due

Microsoft wants Copilot to read your files and act on your PC. Its own security team has already described the risk, and Recall decides who carries it.
Adrian Kessler
Add us on Google

Microsoft is asking Windows users for something it has never asked before: let Copilot open your files, read what you have been working on and act on the machine without you clicking through each step. It is asking from a weak position. The last time the company gave an AI feature a deep view into the PC, researchers took it apart within weeks and Microsoft had to pull it back.

The launch coverage reads like a feature list: local files, local models, a smarter taskbar. The more useful question is what happens to Microsoft if this goes wrong, and on that point the company’s own documents are more candid than its keynote.

What Copilot can now reach on a Windows PC

The new Copilot, shown at Microsoft’s Windows and Surface event, gets what the company calls hybrid intelligence on Copilot+ PCs. With permission, Copilot can understand relevant content on the PC, including files and recent activity, and take actions across Windows: organizing files, assessing device diagnostics, troubleshooting, writing code and running workflows on the device. Some tasks run on local AI models; harder ones go to the cloud. The announcement post, signed by Pavan Davuluri, Microsoft’s executive vice president for Windows and devices, says Copilot “understands your PC, takes action with your permission.”

Autopilot, the agent Microsoft describes as persistent, proactive and personal, gets the same local reach. On stage, Copilot chief Jacob Andreou built his demo around tax season: an email from his accountant and an agent asked to gather what she needed. The taskbar search box, meanwhile, is turning into a command line for thousands of system actions, from switching on dark mode to sending a text message.

Microsoft’s own security team already wrote the warning

The safeguards are real. Activation is opt-in, folder access is restricted and Copilot’s agents run under accounts separate from the user’s, as Crypto Briefing laid out. Microsoft Execution Containers, the sandbox layer that became generally available on Windows 11 at the event, lets organizations define which files and networks an agent can reach. Microsoft says the policy sits outside the agent’s control, so the agent or the code it generates cannot grant itself more access.

The sharpest description of the risk, though, came from inside Microsoft. Dana Huang and Logan Iyer, the corporate vice presidents for Windows security and the Windows platform, wrote earlier this year that agents which “read files, invoke services, modify environments and chain operations together” bring “new risk to control and trust,” and that “LLMs are developing capabilities around escaping sandboxes.” That is the company’s case for containment. It is also a plain account of what it is now shipping to Copilot+ PCs.

Some of the parts that make agent activity auditable are not finished. Microsoft Entra will “soon” tell agent activity apart from user activity, and Intune management of the process containers is also listed as coming soon. A footnote in the announcement adds that “governance at scale may require additional services.” For an IT department, that is the gap between a policy and a promise.

The Recall precedent Microsoft cannot shake

Microsoft has been here before. When it unveiled Recall, the feature that snapshots what appears on screen, security researcher Alex Hagenah found its data stored in a local database and summed it up in one line, quoted by Malwarebytes: “The database is unencrypted. It’s all plain text.” He built a tool that copied it out. Microsoft switched Recall off by default, tied it to Windows Hello and added encryption, then moved it from the broad Copilot+ PC launch into the Windows Insider program, then delayed that preview again.

The second dent came when Davuluri wrote that Windows is “evolving into an agentic OS.” The post drew more than 400 replies, almost all of them negative, and he turned the comments off, The Stack reported. His answer, “We know we have work to do on the experience,” acknowledged the anger. This launch shows the direction did not change.

Why opt-in puts the risk on Microsoft

Opt-in is the right design, and it is also where the accountability lands. Because nothing switches on by default, Copilot’s reach depends on users actively granting access, a point Crypto Briefing made about adoption. Each user who declines is passing judgment on Microsoft’s record more than on the feature. Cryptopolitan noted that the company still carries the privacy concerns Recall created, and that more agent makers signing up to the container system does not automatically make agents safer.

The hybrid features require a Copilot+ PC and are expected to roll out over the coming months, with timing varying by device, market and chip, according to Microsoft. Taskbar search actions began reaching Windows Insiders in the experimental channel on October 7, and an opt-in link between the new Copilot and taskbar search is due in select markets later this year. Microsoft says more than 40 percent of the business laptops now being built are Copilot+ PCs. The Surface Laptop Ultra, its new showcase machine, starts at $2,599 and goes on sale October 16.

Microsoft has built a sandbox that an agent cannot talk its way out of. No container covers the harder part: the first time a Copilot agent moves the wrong file, nobody will blame the model. They will blame Windows.

Tags: , , , ,

Add us on Google

Discussion

There are 0 comments.