Microsoft has taken a step toward creating an “agent-based” operating system, where AI agents autonomously carry out user tasks. However, in an official notice the company directly warns of serious risks: these agents may download and install malicious software without the PC owner’s knowledge. According to Windows Central, the feature is already being tested in experimental builds but is available only to those who explicitly accept the potential threats.

What AI Agents in Windows 11 Are

By “AI agents,” Microsoft refers to modules capable of running in the background: sorting files, sending emails, interacting with applications, and even clicking through the interface like a human. These agents create an isolated environment — a separate desktop and local accounts — but are granted access to the user’s key folders: Documents, Downloads, Desktop, Pictures, Videos, and Music. This level of privilege is necessary for meaningful interaction with the file system but also opens the door to new risks.

By default, the feature is disabled and enabling it requires administrator rights. Microsoft stresses that it should be activated only by users who understand the risks. This is not simply caution — the company acknowledges that AI models can hallucinate and produce unexpected outputs, increasing vulnerability.

Key Threats: From XPIA to Unnoticed Malware Installation

The primary risk is cross-prompt injection (XPIA), an attack in which malicious content (within UI elements, documents, or web pages) intercepts AI instructions and forces the model to perform unwanted actions. As a result, an agent may exfiltrate data, send it to third parties, or — most worryingly — download and install malware. Imagine instructing an AI to organize your files, only for it, influenced by hidden text in a document, to install a trojan without your consent.

Experts note that such vulnerabilities are typical of large language models, which can be manipulated in ways similar to injection attacks in old PHP scripts. In online communities, including Reddit, concerns are already surfacing — from sarcastic jokes about malware installing malware to serious discussions about switching to Linux. Microsoft acknowledges that these are “new threat vectors” that did not exist in traditional operating systems.

Microsoft’s Safety Measures

To minimize risks, the company is implementing several protections:
• Mandatory logging of all agent actions for auditing
• User confirmation for critical operations, such as downloading files
• Restricted access: agents run in isolation and request permissions only when needed

Despite these measures, analysts from Ars Technica and other outlets warn that even with human oversight, XPIA remains a threat, especially if agents interact with the open web. Microsoft presents this as a step toward “human-centered” AI with an animated character reminiscent of Clippy, but critics see more hype than utility.

When to Expect Release

Early test builds with AI agent support are already available to Windows Insider participants. The global rollout has not been announced, but based on Microsoft’s “AI-OS” plans, the feature may become part of a major update in 2026. For now, it is aimed only at experimental users.

In Short

Microsoft is testing AI agents in Windows 11 to automate tasks, but warns they may install malware through XPIA vulnerabilities once given access to user files. The feature is off by default, with logs and confirmations in place, but the risks remain high. Testing is underway in Insider builds, and a full release is uncertain.