The news
On October 7, 2026, at a Windows and Surface event, Microsoft (MSFT) showed a version of Copilot that can reach into files stored on a user's PC. In a demonstration described by The Register, Copilot located tax documents, organized them and drafted an email to an accountant with the files attached. Microsoft says Copilot will only go through documents when a user asks it to, The Register reported.
According to The Register, the capability reaches GitHub Copilot first, the week after October 7, and the Copilot app over the following few months. Local agents run inside Microsoft Execution Containers, which The Register described as agent sandboxes with fine-grained permissions applied at runtime. Crypto Briefing, which also covered the event, listed opt-in activation, restricted folder access and agents running under separate user accounts among the controls Microsoft highlighted.
Google may be heading the same way on Apple's platform. BleepingComputer reported on October 3 that Google is testing a hidden "Additional sandbox options" setting in its Gemini desktop app for Mac, first spotted by TestingCatalog. Text in the interface describes letting Gemini read, create, modify or delete files anywhere on the Mac, open and use apps such as Mail, Safari and Messages, and browse the web without repeated permission prompts.
The feature is not live and Google has not confirmed it, according to BleepingComputer. The interface text says Gemini would still ask for confirmation before sensitive actions such as purchases, money transfers, account creation, accepting legal agreements or changing personal information.
Microsoft is also turning Windows Search into a command line for plain English. On October 7 it began rolling out a preview called Actions to Windows Insiders in the Experimental channel, The Register reported. Typing "mute" silences the speakers and "minimise all my windows" shows the desktop; settings can be changed straight from search results. The preview is English-only and, in The Register's testing, sometimes confused similar phrases such as "turn on" and "switch on".
Why CEOs should care
For CISOs, an assistant that can search, move and attach any file a user can reach turns every overshared folder into a potential leak. Before these features reach managed devices, confirm whether they can be switched off or scoped through device management, which folders and network shares agents may touch, and whether agent actions are logged where your security team can see them. Microsoft's container model is meant to enforce such limits at runtime, so test that it does before you rely on it.
Data governance leads should treat this as a deadline to clean up permissions. Sensitivity labels, retention rules and data loss prevention policies written for humans clicking through folders may not anticipate an agent that searches everything in seconds and drafts an email to an outside address. A demonstration that ends with files attached to an email for an outside accountant is exactly the flow that policy must govern.
Mac-heavy teams should watch the Gemini test closely. A setting that removes repeated permission prompts and allows file deletion anywhere on the machine would conflict with many corporate endpoint policies. Ask Google, and your Mac management vendor, how such a mode could be blocked or audited on company devices.
The bigger picture
The three moves share a goal: make the operating system the place where AI agents act, not just answer. Crypto Briefing argued that Microsoft is leaning on its ownership of the operating system that a large share of the world's PCs run on. BleepingComputer noted that Apple is reportedly considering restrictions on AI agents' access to personal files in macOS, which suggests platform owners may clash with third-party assistants over how much reach they get.
What’s next
Watch for Microsoft's admin documentation on disabling or scoping Copilot file access and agent containers, for Google to confirm or drop the Gemini sandbox option, and for Actions in Windows Search to move from the Experimental channel toward wider Insider builds.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









