Skip to content
Brief Security & Trust ·

AWS releases Strands Box, a sandbox that limits what AI agents can do

The open-source tool is a developer preview that runs only on Apple silicon Macs for now.

In brief
  • AWS released Strands Box on October 7 as an open-source developer preview for Apple silicon Macs. It limits agents using rules that factor in what they did earlier.
  • Some agent actions fall outside its rules, and AWS gave no date for support on Bedrock AgentCore, ECS or Kubernetes.

InfoWorld reported on October 8 that Amazon Web Services (AWS) released Strands Box, an open-source sandbox for AI agents. A sandbox is a walled-off space with limited access. The developer preview came out October 7 under the Apache 2.0 license. For now it runs only on Macs with Apple silicon and macOS 15 or later. Box pairs operating system isolation with rules written in Dogwood, an AWS policy language. The rules can weigh an agent's past actions. Reading a file through the shell, for example, can limit later network requests.

InfoWorld says Dogwood does not cover every action. Files opened through an agent's built-in tools face only operating system limits. AWS said its shell and Python interpreters run outside the sandbox, in a trusted process, which adds parts the system relies on. AWS wants to support Amazon Bedrock AgentCore, Amazon ECS and Kubernetes, but gave no timeline. Analyst Pareekh Jain warned of extra processing load and new flaws. Production results are not yet shown.

Teams that let AI agents touch company apps and data get a rule layer meant to work across agent frameworks, AWS said. Analysts quoted by InfoWorld say identity controls, monitoring and human oversight are still needed.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: InfoWorld.