Microsoft is warning that new agentic features in Windows 11, which allow AI agents to take actions on a user’s behalf, also create fresh security risks. Because these agents can access key folders and automate tasks, attackers could exploit them through techniques like cross prompt injection, where malicious text hidden in files or interface elements tricks the agent into running harmful actions. Security researchers have already shown how this could lead to data exposure or even malware installation if the system is not tightly controlled. As a result, Microsoft is keeping these agentic capabilities turned off by default and requiring administrators to enable them manually, underscoring that users should be cautious until the defenses around these tools mature.

Recent news