The Jerusalem PostIn war-torn Kyiv, Elkin-led Israeli delegation confronts familiar threats while marking Babyn YarESPN DeportesCristiano Ronaldo felicitó a Lionel Messi por su campaña en la Selección ArgentinaRTP DesportoRonaldo homenageia Messi: "Todo o meu respeito pelo que conquistaste com a Argentina"ESPNWhat could these playoffs mean for baseball's labor battle? We asked MLB players, execsDaily MaverickBUSINESS REFLECTION: Loaded for Bear: Red Bull snarled Sandton traffic in a marketing own goalZDF heuteEntdecken Sie das ZDF-NachrichtenstudioBillboardZara Larsson Says She Could Run for Office One Day As the ‘Singing Mamdani’Meduza«Альтернатива для Германии» в Саксонии-Анхальт в своей первой резолюции призовет к прекращению помощи Украине и нормализации отношений с РоссиейBellaNaijaMoët & Chandon Toasts to 20 Years of BellaNaija at the Grand Red Carpet Experience | See PhotosABC News (Australia)CA 'actively' looking at women's schedule as Aussie stars raise concernsBusiness AMIEA bespreekt G7-plan om 100 miljoen vaten olie en diesel vrij te gevenANSADolore e proteste contro il governo, a tre anni dal massacro Israele spaccato
The Daily Newsstand · Free, Always
Wednesday, October 7, 2026

AWS launches open-source AI agent sandbox to prevent YOLO mode disasters

Translate

Strands Box is the latest open source AI control tool from the cloud giant; like its predecessors, it promises tighter reins on autonomous agents

AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. 

Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS’ other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents’ behavior.

“Agents increasingly run in ‘YOLO mode,’ approving every action without human review,” the AWS team explained in its announcement. “The usual solution to this problem is a sandbox … but access is only part of what we want to control.”

REG AD

The problem with containers and microVMs typically used to isolate AI agents, as AWS explains it, is that their strong isolation doesn’t come with contextual rule enforcement. In other words, when a containerized or virtualized agent gets hold of a tool, there may be no stopping it from doing whatever it wants - like deleting a production database, or gaining access to the internet and doing dog knows what.

REG AD

That’s where the other open-source tools inside Strands Box come in: It uses the Dogwood Local Engine to give the policy engine in Box temporal awareness, so tool calls can be checked against not only what the agent wants to do, but what it’s already done. 

As one example, AWS noted that an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent it from spamming its human operators. An AWS spokesperson further explained that Box could be used to control when an agent can perform a Git push, or it could be used to put a cap on API calls that could end up costing a small fortune. 

Additionally, Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions clearer to developers and allowing policies to account for what an agent is trying to do.

AWS VP and distinguished engineer Marc Brooker, one of the folks behind Dogwood and Strands Box, explained to The Register that the interpreters are a key part of making agentic behavior more intelligible, which allows for devs to write more precise policies to prevent agents from taking bad actions. 

“Box’s Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls,” Brooker told us in an email. “Policies can then account for the action being attempted and earlier activity.”

Box, Brooker added, enforces those rules without trusting or relying on agents to actually follow instructions, which should ideally prevent them from running roughshod over their operators’ wishes. 

As for the reason behind AWS’ push to develop open-source tools like Dogwood, the Dogwood Local Engine, and Strands Box, Brooker said that AWS wants to find the right balance between boundaries and policies that prevent agentic AI disasters of the kind we regularly report. 

“Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules,” Brooker explained, though he added that, even with properly configured permissions, an agentic action can still produce an unwanted result.

REG AD

“Developers remain responsible for deciding what access to grant and where human review is needed,” Brooker added - in other words, don’t let your YOLO mode go too YOLO. A bit of human oversight is still necessary. 

“Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source,” Brooker said.

Strands Box supports any agent or harness one wants to confine within its walls and is available on GitHub now, though only for macOS for the time being. Linux support is in development, and AWS told us a Windows client is “on our radar,” but neither has a planned release date. Deployment to platforms like AgentCore, ECS, and Kubernetes is also planned. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.