InfoWorld reported on October 8 that Amazon Web Services (AWS) released Strands Box, an open-source sandbox for AI agents. A sandbox is a walled-off space with limited access. The developer preview came out October 7 under the Apache 2.0 license. For now it runs only on Macs with Apple silicon and macOS 15 or later. Box pairs operating system isolation with rules written in Dogwood, an AWS policy language. The rules can weigh an agent's past actions. Reading a file through the shell, for example, can limit later network requests.
InfoWorld says Dogwood does not cover every action. Files opened through an agent's built-in tools face only operating system limits. AWS said its shell and Python interpreters run outside the sandbox, in a trusted process, which adds parts the system relies on. AWS wants to support Amazon Bedrock AgentCore, Amazon ECS and Kubernetes, but gave no timeline. Analyst Pareekh Jain warned of extra processing load and new flaws. Production results are not yet shown.
Teams that let AI agents touch company apps and data get a rule layer meant to work across agent frameworks, AWS said. Analysts quoted by InfoWorld say identity controls, monitoring and human oversight are still needed.