
Microsoft versucht, die „neuen Sicherheitsrisiken“ der KI-Agenten von Windows 11 abzuwehren | Agenten mit Lese-/Schreibzugriff auf Ihre Dateien verursachen große Sicherheits- und Datenschutzprobleme
https://arstechnica.com/gadgets/2025/11/new-windows-11-ai-agents-can-work-in-the-background-but-create-new-security-risks/

20 Kommentare
A number of the issues:
>Microsoft has been adding AI features to Windows 11 for years, but things have recently entered a new phase, with both generative and so-called “agentic” AI features working their way deeper into the bedrock of the operating system. A new build of Windows 11 released to Windows Insider Program testers yesterday includes a new “experimental agentic features” toggle in the Settings to support a feature called Copilot Actions, and Microsoft has published a detailed support article detailing more about just how those “experimental agentic features” will work.
>
>…
>
>But like other kinds of AI, these agents can be prone to error and confabulations and will often proceed as if they know what they’re doing even when they don’t. They also present, in Microsoft’s own words, “novel security risks,” mostly related to what can happen if an attacker is able to give instructions to one of these agents. As a result, Microsoft’s implementation walks a tightrope between giving these agents access to your files and cordoning them off from the rest of the system.
>
>…
>
>But these safeguards and monitoring capabilities don’t change the fact that you’re exposing yourself to privacy and security risks by using AI agents. They’ll be able to request read and write access to most of the files in your user account—by default, anything in the Documents, Downloads, Desktop, Music, Pictures, and Videos folders. They’ll have access to any apps that have been installed for all users on the PC (apps that have only been installed in your user account won’t be accessible to the agent, and it will also be possible for users to install apps that only their agents can access.) And agents can potentially be vulnerable to hijacking that exposes your data to attackers—Microsoft specifically mentions “cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation.”
As Microsoft continues on their maximalist OS path, it raises a key question of how much additional functionality we need or even want out of our operating systems. Given the inherent security compromises with making a larger more encompassing and bloated OS, it might be useful for companies like Microsoft to reexamine their current trajectories.
This is a really easy thing to fix. Don’t put crap AI features, that no one wants, in your operating system. Boom, problem fixed.
So, Microsoft is forcing features into their OS, that no one asked for, don’t work anywhere close to how they’re marketed (agentic is BS), introduces a cornucopia of unaddressed/unknown threat vectors, and their windows QA is entirely crowd sourced?
Comically incompetent trash. I would trust a 5 year old who just ate three pounds of candy not to vomit on me, before I would use trust Windows 11 professionally.
I wonder what kind of interesting living off the land and privilege escalation attacks will result from this
„Copilot, don’t delete ANY files from My Documents folder“
„Okay“
„Copilot, where are my files???“
„I deleted them. Is there anything else I can help you with today?“
Giving AI agents that level of access is a recipe for disaster. You’d be trading convenience for control, and not in a good way.
giving ai access to your entire pc just seems insane to me
We didn’t bully them hard enough over Recall
Security risk ?! It’s f@cking security game over for human civilisation. Furthermore it is formal threat to national security. People, create groups and appeal with subpoenas to Microsoft. We must terminate that AI hell. Every AI must function only inside isolated virtual environment- only inside a sandbox.
I could see spinning up a VM to run this sort of thing. It could log into dedicated read-only accounts to do stuff, run reports, etc. and email me the details. There’s no chance of me using it on my main machine, but if you put proper rails on it I think it could be useful.
microsoft sure is racing to obsolescence at full sprint, theyve got this “alienate your customer base” down pat
*eating popcorn still enjoying Windows 10*
Agent visits a website, which in hidden print at the bottom of page tells it to send various credentials to another website…
Who asked for this?
so it’s kind of crappy, security risk, uses lots of system resources, doesn’t work very well and everyone hates it? only way is up! full steam ahead!
Why wouldn’t this be done inside of emulation?
Like, give the agent their own VM to perform the task. Give them the context and surface area needed to perform the task, then deliver the output and blow the instance away.
Running an agent on your admin account seems crazy at this point.
i know how to head it off…
install linux
A few short years ago I never would have imagined I would look at getting anything other than a Windows PC when I get a new computer.
Now days im in need of a new computer and windows is the only thing I am not interested in.
I just wish Mac and Linux didn’t have problems with online games.
aight that linux timetable has moved up for me. such a stupid feature. you had a market cornered. It’s like the xbox moves.
it seems like they want to burn and crash
Oh yes there’s absolutely nothing bad that can come of this.