Microsoft announced general availability of Execution Containers (MXC) for Windows agents on Wednesday, and NVIDIA opened preorders for RTX Spark laptops built to run those agents. The two companies presented both at a Microsoft event in San Francisco. The software is the part a Windows user can rely on first. The hardware comes later.

Four things were announced, and they sit at different stages, according to the NVIDIA blog post by Gerardo Delgado:

The post gives no price for any of them.

Microsoft describes MXC as operating-system infrastructure that lets agents keep running in the background under the control of Windows. Pavan Davuluri, Microsoft’s EVP of Windows and Devices, said agents should be “secured, observed and governed.” Satya Nadella said Microsoft wanted the desktop to be the safest place for an agent to run.

An agent with access to your files is a different security problem from a chatbot in a browser tab. It can read and change real documents, and it keeps working after you look away. A container is meant to draw a boundary around that process, so an agent that misbehaves or gets manipulated cannot reach everything else on the machine. That is the general idea. NVIDIA’s post does not say what MXC walls off, what permissions an agent gets by default, or how a user sees what an agent did. “Observed” and “governed” imply logging and policy, yet the post supplies no mechanics and cites no outside security review.

On hardware, NVIDIA says RTX Spark pairs a Blackwell GPU that tops out at 6,144 cores and a Grace CPU with up to 20 cores, linked at 600 GB/s. It lists up to 128GB of unified memory and a petaflop of FP4 compute. FP4 is a four-bit number format, the lowest precision in common use, so that figure is a best case. Acer, ASUS, Dell, HP, Lenovo, Microsoft, MSI, and Gigabyte are named as system makers, including a Surface Laptop Ultra built around the chip.

The headline model claim is also NVIDIA’s. The post says RTX Spark can run Qwen 3.8 Flash Next, “a 125B model with 51B n-gram,” and NVIDIA describes it as one that “matches the intelligence of many cloud models,” running unmetered with no data leaving the machine. The post names no benchmark, no quantisation level, and no speed in tokens per second. It does not explain the “51B n-gram” label. Treat the claim as a spec sheet line until someone measures it.

DGX Station for Windows is the larger machine. NVIDIA lists a GB300 Grace Blackwell Ultra superchip with 748GB of coherent memory and as much as 20 petaFLOPS at FP4, which it says is enough for models up to trillion-parameter scale locally. Until now the product ran Linux. A Windows version matters to enterprises that standardise on Windows, but with no date and no price it is a roadmap item.

The strategic logic is ours, not a claim in the post. Data-center GPUs go to a short list of very large buyers with the leverage to negotiate. A laptop or deskside box sells to every Windows customer, and NVIDIA stresses that the same CUDA stack runs from RTX Spark up to DGX Station, so work built on a laptop is ready to move up the product line. For Microsoft, an agent whose inference runs on hardware the customer bought puts the compute bill on the customer, and MXC makes Windows the layer that governs agents whichever model runs underneath.

Privacy is a real benefit of local inference, but the larger shift is who pays. “Unmetered” means the user pays up front and in electricity instead of per token. Buyers with steady, heavy agent workloads and sensitive files gain most. Both vendors gain regardless.

The number to run before October 16 is the break-even between a laptop of undisclosed price and a year of per-token bills for the same agent. The number nobody can run yet is what MXC actually blocks.

Reported by Gerardo Delgado on the NVIDIA blog, published 7 October 2026; every performance and availability claim above is NVIDIA’s own.