Microsoft unveiled Project Zenith, a developer-focused Windows 11 configuration for high-memory PCs that can run AI models exceeding 30 billion parameters locally. The initiative targets systems with at least 64 GB of unified memory and more than 250 GB/s memory bandwidth; initial devices will use AMD Ryzen AI Halo, with additional OEM and silicon partners expected.
Zenith combines Windows performance tuning and developer-oriented defaults with integrated WSL containers and Microsoft Execution Containers. Microsoft said the configuration provides containment, identity controls, and enterprise management for agentic-development workloads, enabling routine AI-assisted development to move from metered cloud inference to on-device models while retaining cloud services for more demanding tasks.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
At IFA 2026, Microsoft presented its "unmetered intelligence" vision for Windows, emphasizing local execution of AI workloads on CPUs, GPUs, and NPUs alongside cloud services. The company also described plans for Windows AI-agent tooling, isolation containers, and future auditing, logging, and policy controls.
Microsoft said it developed Microsoft Execution Containers with NVIDIA and silicon partners to isolate, apply policy to, and log autonomous Windows agents. NVIDIA plans to integrate its OpenShell agent framework with the containers; Hermes Agent and OpenClaw were identified as OpenShell integrations.
Microsoft introduced Project Zenith, a developer-focused Windows 11 configuration for high-memory PCs intended to run AI models exceeding 30 billion parameters locally. The configuration targets systems with at least 64 GB of unified memory and more than 250 GB/s memory bandwidth, initially using AMD Ryzen AI Halo, and includes WSL containers and Microsoft Execution Containers for managed agentic-development workloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourcehelpnetsecurity.com
Open sourcewindowslatest.com
Open sourcetomshardware.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.