Microsoft has announced a major upgrade to its Copilot AI integration in Windows 11, introducing a new feature called Copilot Actions. This feature enables AI agents to perform real tasks on users' local files and applications, moving beyond simple chatbot interactions to more advanced, agentic capabilities. Copilot Actions allows users to interact with their PC using natural language, voice commands, and visual cues, enabling the AI to open and close apps, update documents, organize files, book tickets, and send emails on behalf of the user. The feature is currently being tested by members of the Windows Insider Program and will eventually be rolled out to all Windows 11 PCs, regardless of whether they are classified as Copilot+ devices. Microsoft has emphasized the importance of security and privacy in the design of Copilot Actions, especially in light of previous controversies such as the Recall feature. To address potential risks, Copilot Actions requires explicit user permission before taking any action, and users retain the ability to control or revoke access at any time. Each AI agent operates within its own isolated Agent Workspace, ensuring that actions taken by one agent do not affect others or the broader system. Agents run under distinct standard Windows accounts with no administrative privileges, and their activities are governed by strict application and file system access rules. Microsoft has also implemented operational trust measures, such as digitally signed agents, and all agent activities are subject to the Microsoft Privacy Statement and Responsible AI Standard. The company is optimizing these workspaces to minimize any impact on system performance and has confirmed that there will be no changes to Windows 11 hardware requirements. The introduction of Copilot Actions represents a significant shift in how users interact with their PCs, transforming AI from a passive assistant to an active digital collaborator. However, this evolution also raises new questions about trust, as users must decide whether to allow AI agents access to sensitive files and applications. Microsoft is addressing these concerns by building in robust security guardrails and transparency around agent actions. The company is taking a cautious approach, learning from past experiences and ensuring that security controls are in place before the feature becomes widely available. As Copilot Actions moves from testing to general availability, Microsoft is expected to continue refining its security and privacy measures based on user feedback and ongoing risk assessments. The rollout of Copilot Actions is part of Microsoft's broader vision to deeply integrate AI into the Windows desktop environment, aiming to enhance productivity while maintaining user trust and system integrity. Security professionals and CISOs should closely monitor the deployment of Copilot Actions, assess the potential risks associated with agentic AI, and ensure that organizational policies are updated to address these new capabilities. The evolution of Copilot in Windows 11 underscores the growing importance of balancing innovation with security and privacy in the age of AI-driven computing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced broader Copilot upgrades for Windows 11, including capabilities that let Copilot hear and see, alongside new AI agent functionality. Later coverage framed these features as part of Microsoft's next major high-stakes AI push in Windows.
Microsoft introduced Copilot Actions, a new agentic AI capability for Windows that can perform tasks on a user's behalf. Multiple references on the same day describe this as a major new Copilot feature rollout for Windows 11.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcezdnet.com
Open sourcezdnet.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.