AWS Sandbox Targets Rogue AI Agents
AWS's new Strands Box uses OS isolation and custom policies to curb AI agent behavior, but security experts warn controls have gaps.
As enterprises hand AI agents the keys to applications and data, a runaway script or a misconfigured model can cause real damage. Amazon Web Services has stepped into that gap with an open-source sandbox designed to constrain what agents can do—not just by static permissions, but by reacting to what they have already done.
The tool, called Strands Box, was released in developer preview on October 7 under the Apache 2.0 license. It combines operating system-level isolation with a policy engine that evaluates each action an agent attempts. For now, it only runs on Macs with Apple silicon processors running macOS 15 or later, a limited starting point that AWS says it intends to expand.
Policy engine learns from past actions
At the heart of Strands Box is Dogwood, an open-source policy language developed by AWS, and an evaluation engine that decides whether an agent should be allowed to perform a given action. The engine can factor in an agent’s recorded activity across different tools, meaning a file read through a shell command could trigger restrictions on subsequent network requests.
That cross-tool correlation is what sets it apart from simpler allow/deny lists. AWS offered a concrete example in its announcement: "Consider an agent investigating a production incident," the company wrote. "We want it to post progress updates to the incident channel in Slack as it finds things, but not to flood the channel and bury the updates from humans. A policy can let the agent post, but no more than three times every 10 minutes. The agent can keep investigating, while Box enforces the posting limit without relying on the agent to remember it."
Strands Box checks actions routed through its shell and Python interpreters, as well as through its broker for the Model Context Protocol (MCP). By default, its network gateway evaluates outbound requests against policies and can attach credentials to approved requests without exposing the secrets to the agent.
Designed to be framework-agnostic
AWS said the approach is intended to provide controls independent of the AI agent framework, reducing reliance on permission mechanisms built into individual agents. That matters because many agent frameworks today have their own, often inconsistent, security models. A common policy layer could give security teams a single place to define rules that apply across different agent implementations.
"Strands Box addresses a real security gap, although its underlying technologies are not new," said Pareekh Jain, CEO of Pareekh Consulting. "Its main advantage is making security easier to enforce consistently across different AI agent frameworks."
Jain’s point about the technology not being new is worth noting: sandboxing and policy engines have existed for years. What is new here is applying them to the specific problem of autonomous agents that can chain actions together in unpredictable ways.
Security gains come with trade-offs
The added controls are not without cost. Dogwood’s policies do not cover every action an agent can take. Files accessed directly through an agent harness’s built-in tools, for instance, remain subject to operating system-level restrictions but are not evaluated by Dogwood’s policy engine. That creates a potential blind spot where an agent could bypass policy checks by using native file access.
AWS also acknowledged that its shell and Python interpreters run outside the sandbox as part of a trusted process, expanding the number of components whose security the system depends on. In other words, the security of the sandbox now hinges on the security of those interpreters as well.
Jain cautioned that the additional security controls could increase processing overhead and introduce new components that might themselves contain vulnerabilities. More moving parts mean more attack surface, even when those parts are meant to provide protection.
"Poorly designed policies could block legitimate agent actions or create operational complexity, while overly permissive policies could still leave gaps," said Tulika Sheel, senior vice president at Kadence International.
"It cannot prevent every harmful decision an agent makes within its allowed permissions," Jain said. "Enterprises will still need IAM, monitoring, and human oversight."
That caveat is important. Strands Box is a guardrail, not a cure-all. It can stop an agent from posting too many Slack messages or reading sensitive files after a suspicious network request, but it cannot judge intent. If an agent is permitted to send emails, it can still send a harmful one—just not more than the policy allows.
Portability will test adoption
AWS said it wants to expand support beyond macOS and enable developers to deploy agents with their policies intact across platforms such as Amazon Bedrock AgentCore, Amazon ECS, and Kubernetes. The company has not provided a timeline for those capabilities.
Until then, Strands Box remains a Mac-only tool. That limits its immediate usefulness for enterprises running agents in Linux containers or on cloud infrastructure, which is where most production deployments live. The developer preview label also signals that the tool is not yet ready for mission-critical workloads.
Jain said a common policy layer could let developers concentrate on building agents while security teams maintain common rules. Adoption would depend on broader platform support and how much overhead policy enforcement introduces, he added.
Sheel said the open-source approach could help adoption, but enterprises would need evidence that the controls work reliably in production before adopting them widely.
"As agents become more autonomous, behavioral controls could become as fundamental to AI infrastructure as identity and access management are today," Sheel said.
Why it matters: guardrails for autonomous systems
For businesses experimenting with AI agents, the launch of Strands Box is a reminder that autonomy and security are not mutually exclusive—but they require deliberate design. The tool’s policy language and cross-tool correlation offer a way to enforce limits that agents themselves cannot override, which could reduce the risk of accidental data exfiltration, API abuse, or runaway cloud costs.
However, the gaps identified by AWS and the external experts suggest that no single sandbox can provide complete protection. Enterprises will still need layered defenses: strong identity and access management, continuous monitoring, and human oversight. The open-source nature of Strands Box may encourage adoption and scrutiny, but its current macOS-only preview means most organizations will have to wait before they can standardize on it.
As agents take on more responsibilities, the ability to constrain their behavior after deployment could become a baseline requirement, much like firewalls and endpoint detection are today. AWS’s move, even with its limitations, points in that direction. The question is whether the industry will converge on interoperable controls or continue to rely on framework-specific, fragmented protections.
Sources
- CSO Online Original source
Continue Reading
AWS sandbox aims to tame rogue AI agents
Amazon's new open-source Strands Box uses OS-level isolation and policy rules to stop autonomous agents from going rogue.
Melius bets on ad creative after a full reset
Ex-Ramp engineers raise $25M for Melius, an AI platform for generating ad campaigns, after scrapping their first product entirely.
Ghost's $3,499 AI box sells out first run
A teen-founded startup says its on-device AI computer sold out its first batch, betting privacy beats cloud convenience.