4 Sources
[1]
I get why some people are suddenly freaking out about AI agents in Windows 11 - I'm worried, too, but let's not panic just yet
Windows 11 is in the firing line once again, and this time some recent updates to documentation around AI agents have provoked fresh concerns about how these entities will work in the OS - and what threats they might pose. This latest controversy actually stems from an old support document about
[2]
Microsoft confirms that its new AI agent in Windows 11 hallucinates like every other chatbot and poses security risks to users
Hallucinating, hack-prone operating systems are the new normal. Like the rest of the tech world and its LLM-powered pooch, Microsoft has been on a big AI push of late. Its latest achievement in that regard is the rollout of agentic AI capabilities for Windows 11 courtesy of the 26220.7262 update
[3]
Microsoft confirms its Windows 11 AI Agents hallucinate and pose a serious security risk
TL;DR: Microsoft's Windows 11 is evolving into an AI-powered "Agentic OS," featuring background AI Agents with separate accounts that perform tasks via natural language. While enhancing productivity, these experimental features pose significant security risks like data leaks and malware, prompting
[4]
Microsoft's AI obsession is scaring me
There was a time when I opened Windows and felt in control. Now? I feel like I'm living in Microsoft's experiment lab. Even after four years of launch, Windows 11 still feels like a work in progress. It started innocuously enough. A feature here, an AI integration there. But somewhere along the
Share
Copy Link
Microsoft updated documentation for Windows 11's Experimental Agentic Features, confirming AI agents can hallucinate and pose security risks including cross-prompt injection attacks. The company warns users to understand security implications before enabling these experimental features, sparking concerns about privacy and the future of the operating system.

Microsoft has updated its documentation for Windows 11's Experimental Agentic Features, revealing that AI agents can hallucinate and introduce novel security risks to users
1
. The update coincides with the deployment of preview version 26220.7262 in the Dev and Beta channels, which includes the first agent, Copilot Actions1
. This feature can work with files on your PC to organize photos and delete duplicates, but the documentation now contains warnings that have alarmed privacy advocates and tech experts alike.The company explicitly states that "AI models still face functional limitations in terms of how they behave and occasionally may hallucinate and produce unexpected outputs"
3
. More concerning, Microsoft acknowledges that agentic AI applications introduce security risks such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation2
.Microsoft's vision for an Agentic OS involves AI agents running in the background with their own accounts and privileges, creating a scenario where multiple users are logged into your PC simultaneously
3
. These agents are designed to handle tasks through natural language interactions, from launching office apps and creating charts to browsing for deals and searching through images. Copilot serves as the primary interface for these autonomous entities.To contain potential threats, Microsoft has implemented an 'agent workspace' system where agents operate as separate local users with distinct accounts completely walled off from the user's account
1
. These agents have limited file access based on permissions granted, aside from a handful of default folders. The architecture theoretically keeps agents contained, so even if compromised, they should only have limited means of exploiting the system. However, the effectiveness of these safeguards remains to be proven in real-world deployment.The most troubling aspect of Microsoft's recent documentation update is a new caution stating: "We recommend you read through this information and understand the security implications of enabling an agent on your computer"
1
. This language effectively shifts responsibility onto users, many of whom lack the technical expertise to assess such risks. How is a typical user meant to judge the likelihood of a successful attack that relies on XPIA vulnerabilities2
?Microsoft outlines three core principles for its agentic security and privacy approach: all agent actions are observable and distinguishable from user actions; agents that handle protected data meet or exceed security standards; and users approve all queries for user data and actions taken
2
. Yet these principles appear to be aspirations rather than guarantees, given the prominent security warnings. The Experimental Agentic Features are not enabled by default, but once switched on, they're enabled for all users, all the time2
.Related Stories
Cross-prompt injection represents a particularly insidious threat. A user could download a PDF containing hidden text instructing the Windows agent to execute nefarious tasks, and the agent might simply carry out those instructions
2
. Beyond XPIA, cascading AI hallucinations pose another risk, where the AI generates false or misleading information that stays in its memory and can trigger real-world consequences4
. An agent could make incorrect API calls, pull wrong regulatory criteria, or pass fabricated information to other systems.The problem intensifies because Copilot requires access to everything from Microsoft 365 data, emails, documents, and communications to be useful
4
. When it starts taking autonomous actions, any mistake can cause significant damage. Microsoft has been aware of these attack vectors since last year, building its systems with these threats in mind1
. The question remains whether the defenses will prove tight enough to deflect attempted intrusions.Industry observers note that Microsoft appears to feel overwhelming competitive pressure to add these features to Windows 11, risking being overtaken by competitors who will
2
. This urgency has led to a remarkable shift in norms around reliability and safety, with Microsoft essentially releasing features with major known flaws and security vulnerabilities. The approach marks a departure from traditional software development practices where such issues would typically be resolved before public release.Microsoft's previous misstep with Recall—an AI feature that takes screenshots every five seconds and indexes everything—doesn't inspire confidence
4
. Security experts identified vulnerabilities that could allow attackers to scrape everything a user has ever done in seconds. While Microsoft shelved and later relaunched Recall as opt-in, the pattern of rushing AI features to market with acknowledged security gaps continues with these new AI agents. Users are left wondering whether Microsoft has truly learned from past mistakes or if they're simply accepting buggy and insecure as the new normal for AI-powered features.Summarized by
Navi
[3]
[4]
18 Nov 2025•Technology

03 Jul 2026•Technology

12 Nov 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology