Local inference changes where a model runs, not what its agent tools can reach
Source: Microsoft
Microsoft says GitHub Copilot will add automatic selection between on-device and cloud models by the end of October, alongside explicit local-model selection. Its Microsoft Execution Containers apply operating-system controls to shell commands and, by default, local MCP servers when sandboxing is enabled. Built-in file tools are checked by the Copilot harness rather than isolated as child processes, and remote MCP servers remain outside the local process sandbox. The announcement describes different enforcement paths, not a universally offline or isolated Copilot session.
Why this matters: Separate the model-placement decision from permission design. For each coding or operations agent, record whether prompts and context can move to a cloud model, which local files and network destinations tools can reach, and how credentials are supplied. Test the actual shell, built-in file, and remote-tool paths against a denied read, write, and outbound call before relying on a sandbox label. Recheck the automatic-routing feature when it ships; a planned release is not a control already available in every tenant.
Read Microsoft's local models and sandboxed tools announcement