
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it's adding a full-on sandbox to this stack. Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS' other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents' behavior. Agents increasingly run in YOLO mode,' approving every action without human review," the AWS team explained in its announcement. The usual solution to this problem is a sandbox ... but access is only part of what we want to control." The problem with containers and microVMs typically used to isolate AI agents, as AWS explains it, is that their strong isolation doesn't come with contextual rule enforcement. In other words, when a containerized or virtualized agent gets hold of a tool, there may be no stopping it from doing whatever it wants - like deleting a production database, or gaining access to the internet and doing dog knows what. That's where the other open-source tools inside Strands Box come in: It uses the Dogwood Local Engine to give the policy engine in Box temporal awareness, so tool calls can be checked against not only what the agent wants to do, but what it's already done. As one example, AWS noted that an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent it from spamming its human operators. An AWS spokesperson further explained that Box could be used to control when an agent can perform a Git push, or it could be used to put a cap on API calls that could end up costing a small fortune. Additionally, Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions clearer to developers and allowing policies to account for what an agent is trying to do. AWS VP and distinguished engineer Marc Brooker, one of the folks behind Dogwood and Strands Box, explained to The Register that the interpreters are a key part of making agentic behavior more intelligible, which allows for devs to write more precise policies to prevent agents from taking bad actions. Box's Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls," Brooker told us in an email. Policies can then account for the action being attempted and earlier activity." Box, Brooker added, enforces those rules without trusting or relying on agents to actually follow instructions, which should ideally prevent them from running roughshod over their operators' wishes. As for the reason behind AWS' push to develop open-source tools like Dogwood, the Dogwood Local Engine, and Strands Box, Brooker said that AWS wants to find the right balance between boundaries and policies that prevent agentic AI disasters of the kind we regularly report. Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules," Brooker explained, though he added that, even with properly configured permissions, an agentic action can still produce an unwanted result. Developers remain responsible for deciding what access to grant and where human review is needed," Brooker added - in other words, don't let your YOLO mode go too YOLO. A bit of human oversight is still necessary. Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source," Brooker said. Strands Box supports any agent or harness one wants to confine within its walls and is available on GitHub now, though only for macOS for the time being. Linux support is in development, and AWS told us a Windows client is on our radar," but neither has a planned release date. Deployment to platforms like AgentCore, ECS, and Kubernetes is also planned. (R)