Updated
Updated · InfoWorld · Oct 8
AWS Launches Strands Box Sandbox for AI Agents, Limiting Slack Posts to 3 per 10 Minutes
Updated
Updated · InfoWorld · Oct 8

AWS Launches Strands Box Sandbox for AI Agents, Limiting Slack Posts to 3 per 10 Minutes

3 articles · Updated · InfoWorld · Oct 8

Summary

  • AWS released Strands Box in developer preview on Oct. 7 as an Apache 2.0 open-source sandbox that can restrict AI agent actions based on prior behavior rather than one-off permissions.
  • Dogwood, AWS’s policy language, evaluates actions across shell, Python and MCP-brokered tools, so one step—such as reading a file—can shape whether later network requests are allowed.
  • By default, the network gateway checks outbound requests against policy and can attach credentials to approved calls without exposing secrets to the agent, aiming to work independently of any single agent framework.
  • Mac support is currently limited to Apple silicon systems running macOS 15 or later, and AWS acknowledged gaps: some built-in tool actions bypass Dogwood checks while trusted interpreters run outside the sandbox.
  • Analysts said the approach could help standardize security across agent frameworks, but wider adoption will hinge on broader platform support, production reliability and the processing overhead of policy enforcement.

Insights

Could AWS's new Strands Box and its history-aware policies be the ultimate cage for autonomous AI, or just a fragile illusion?
Will complex Dogwood policies successfully govern enterprise AI, or will they cause unexpected agent paralysis and block legitimate autonomous workflows?