Content
summary Summary

Microsoft is adding a feature to 365 Copilot that lets AI agents handle web tasks on their own, pushing automation in knowledge work a step further.

Ad

The new “Researcher with Computer Use” tool acts like an autonomous browser agent, similar to the ChatGPT agent. It can click, navigate, and run code to automate complex searches, analysis, and report generation.

Each session runs inside a sandboxed virtual machine (VM) created with Windows 365. This isolated cloud computer includes its own browser, terminal, and text editor, and remains completely separate from both the company network and the user’s device. Microsoft says login data isn't stored or transmitted.

The agent can access information behind logins, such as paywalled articles or company databases, if the user or admin approves. When access is needed, the system asks for confirmation, letting the user step in to log in or approve specific actions.

Ad
Ad

Microsoft gives an example where the agent downloads a World Bank dataset from the terminal and uses Python to analyze national savings rates.

Admins manage access, but security risks persist

By default, the tool blocks company data like emails, SharePoint, and meetings. Users can share specific data sources, but administrators decide which user groups get access, what data can be combined, and which websites are allowed. Microsoft says all sandbox activity can be audited.

Even with these safeguards, autonomous AI systems still pose security challenges, especially when interacting with external content. Studies continue to warn about the risks of letting AI agents operate freely on the open web.

Ad
Ad
Join our community
Join the DECODER community on Discord, Reddit or Twitter - we can't wait to meet you.
Support our independent, free-access reporting. Any contribution helps and secures our future. Support now:
Bank transfer
Summary
  • Microsoft is adding a feature to 365 Copilot that allows AI agents to operate autonomously on the web, handling actions like navigating, clicking, and running code to automate complex tasks such as research and analysis.
  • These operations are performed in an isolated Windows 365 virtual machine, which is reset for every session and kept completely separate from both the company network and the user's device.
  • The AI agent can also access content behind logins, such as paywalled articles or internal company databases, as long as it has the required permissions.
Sources
Matthias is the co-founder and publisher of THE DECODER, exploring how AI is fundamentally changing the relationship between humans and computers.
Join our community
Join the DECODER community on Discord, Reddit or Twitter - we can't wait to meet you.