Security News

AWS Releases Open-Source Sandbox to Rein In Autonomous AI Agents

The Register · 8 Oct 2026
Key Takeaway If your business is trialling AI agents, limit what they can access and set clear rules on what actions they can take and how often, rather than relying on isolation alone.

Amazon Web Services has released Strands Box, an open-source sandbox designed to keep tighter control over autonomous AI agents. AWS says agents increasingly run in "YOLO mode", approving every action without human review. Containers and microVMs, commonly used to isolate agents, give strong separation but may not enforce contextual rules. That means an agent given access to a tool could still do something damaging, such as deleting a production database or reaching the internet.

Strands Box tries to close that gap using OS-level isolation plus other recent AWS open-source tools. The Dogwood Local Engine gives its policy engine a sense of time, so tool calls are checked against both what an agent wants to do and what it has already done. AWS gave examples: letting an agent post to Slack no more than three times every ten minutes, controlling when it can perform a Git push, or capping API calls that could become costly. Strands Shell and Monty for Python expose shell and Python operations to the same policy engine and event history.

AWS VP and distinguished engineer Marc Brooker told The Register that these interpreters make agent behaviour easier to understand, helping developers write more precise policies that block bad actions. This summary is based on the opening of the article, not the full story.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.