AWS launches open-source sandbox to constrain AI agent actions

AWS has released Strands Box, an open-source sandbox for AI agents, in developer preview under the Apache 2.0 license. It combines operating system isolation with the Dogwood policy language to restrict agent actions based on prior activity, initially supporting Apple silicon Macs running macOS 15 or later. The tool aims to provide consistent security controls across different agent frameworks, though it introduces trade-offs around trusted code.
AWS unveiled Strands Box on October 7 as a developer-preview tool under Apache 2.0. It runs on Apple silicon Macs with macOS 15 or newer, using operating-system isolation instead of a separate virtual machine. Its Dogwood policy engine can consider an agent's earlier actions across tools, so one step may affect later permissions.
The sandbox inspects activity through shell and Python interpreters and an MCP broker. A network gateway can check outbound traffic and add credentials to approved calls without revealing secrets to the agent. Some direct file access and trusted interpreter processes fall outside Dogwood's policy checks, AWS noted.
Strands Box could give enterprises a more consistent way to limit autonomous agents as they gain access to data and applications. Developers and security teams may benefit from reusable policies, but added components and policy design could create overhead or new failure points. Poorly tuned rules might block legitimate work, while permissive ones may leave risks. Because coverage is partial and macOS-only for now, organizations may still rely on identity controls, monitoring, and human oversight. Broader platform support could shape adoption and how safely agentic systems spread.