<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2" -->

---
title: AWS releases Strands Box, an open-source sandbox that...
description: AWS released Strands Box, an open-source sandbox for AI agents that combines OS-level isolation with Dogwood, a new policy language and evaluation engine that...
canonical: https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AWS releases Strands Box, an open-source sandbox that limits AI agents based on what they've already done | daily.dev
og:description: AWS released Strands Box, an open-source sandbox for AI agents that combines OS-level isolation with Dogwood, a new policy language and evaluation engine that...
og:url: https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2
og:image: https://api.daily.dev/og/posts/aAgpZKql2.png
og:image:alt: AWS releases Strands Box, an open-source sandbox that limits AI agents based on what they've already done
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS releases Strands Box, an open-source sandbox that limits AI agents based on what they've already done

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

AWS released Strands Box, an open-source sandbox for AI agents that combines OS-level isolation with Dogwood, a new policy language and evaluation engine that tracks an agent's history of actions. Unlike containers or microVMs, Box can apply rules based on what an agent already did, such as rate-limiting Slack posts, controlling Git pushes, or capping API spend. It monitors shell, Python, and MCP broker activity, gates network requests, and injects credentials without exposing them to the agent. The developer preview launched October 7 under Apache 2.0, but currently only supports Macs with Apple silicon on macOS 15+; Linux, Windows, and deployment targets like Bedrock AgentCore, ECS, and Kubernetes are planned without a timeline. Analysts note it fills a real security gap but adds trusted components and overhead, and doesn't replace IAM, monitoring, or human oversight.

## Content

AWS has released Strands Box, an open-source sandbox for AI agents. It pairs operating system-level isolation with Dogwood, a new AWS policy language and evaluation engine. The point is to let a policy look at an agent's earlier actions before deciding whether to allow the next one.

It entered developer preview on October 7 under the Apache 2.0 license and is on GitHub now.

## What it does

Containers and microVMs isolate an agent from the host, but they don't know what the agent did five minutes ago. Box does. Because it records an agent's prior activity, rules can depend on context. A few examples of what a policy can express:

- Rate-limit how often an agent posts to Slack.
- Control when it can push to Git.
- Cap how much it spends on API calls.

The rules are deterministic, so an agent can't talk its way around them the way it might with a prompt-based guardrail. Box can also gate network requests and attach credentials on the agent's behalf without exposing the secrets to the agent itself.

To get shell and Python activity in front of the policy engine, Box bundles Strands Shell and Monty for Python. It evaluates actions from the shell, the Python interpreter, and the MCP broker.

## Limits

The preview only runs on Macs with Apple silicon on macOS 15 or later. AWS says it plans to add Linux and Windows, along with deployment targets including Bedrock AgentCore, ECS, and Kubernetes. It hasn't given a timeline.

AWS also stresses that developers are still responsible for configuring access correctly.

Analysts see the approach as filling a real gap in agent security, but they point to trade-offs:

- Actions from an agent harness's built-in tools fall outside what Box evaluates.
- The bundled shell and Python interpreters add trusted components outside the sandbox, which widens the code you have to trust.
- Policy evaluation may add processing overhead.
- It doesn't replace IAM, monitoring, or human oversight.

I think the stateful part is the interesting bit. Most sandboxing treats every call as if it were the first, and that's not how agents go wrong. They go wrong by doing something reasonable forty times in a row.

## Questions this post answers

### What is AWS Strands Box and how is it different from a regular container sandbox for AI agents?

Strands Box is an open-source sandbox for AI agents that pairs OS-level isolation with Dogwood, a policy language and evaluation engine tracking an agent's prior actions. Unlike containers or microVMs, which isolate an agent without memory of its history, Box applies deterministic rules based on what the agent already did, such as rate-limiting Slack posts or capping API spend.

_Developers evaluating agent sandboxing options can follow releases like this one on daily.dev._

### What platforms does AWS Strands Box support right now?

The developer preview, released October 7 under the Apache 2.0 license, only supports Macs with Apple silicon running macOS 15 or later. AWS plans to add Linux and Windows support along with deployment targets including Bedrock AgentCore, ECS, and Kubernetes, but has not given a timeline for these additions.

_Teams planning agent infrastructure rollouts can track platform support updates via daily.dev._

### Does AWS Strands Box replace the need for IAM and access controls when running AI agents?

No, Strands Box does not replace IAM, monitoring, or human oversight. Analysts note it fills a real gap in agent security by applying history-aware, deterministic rules, but developers still must configure access correctly themselves, and the sandbox adds trusted components outside the isolation boundary along with some performance overhead.

_Engineers weighing agent security trade-offs can keep up with analyst takes through daily.dev._

## Similar posts on daily.dev

- [AWS creates a sandbox for its agent experiments](https://daily.dev/posts/aws-creates-a-sandbox-for-its-agent-experiments-r5p1skjmm) · The New Stack · 0 upvotes · 0 comments
- [AWS Launches Strands Labs for Experimental AI Agent Projects](https://daily.dev/posts/aws-launches-strands-labs-for-experimental-ai-agent-projects-h0ycai6cx) · InfoQ · 1 upvotes · 0 comments
- [Protect AWS Strands Agents with Datadog AI Guard](https://daily.dev/posts/protect-aws-strands-agents-with-datadog-ai-guard-ozdg3ew0p) · Datadog · 2 upvotes · 2 comments

---

Tags: [#aws](https://daily.dev/tags/aws), [#ai-agents](https://daily.dev/tags/ai-agents), [#ai-security](https://daily.dev/tags/ai-security)

[View this post on daily.dev](https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AWS releases Strands Box, an open-source sandbox that limits AI agents based on what they've already done","url":"https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2"},"datePublished":"2026-10-08T13:14:26.875Z","dateModified":"2026-10-08T14:37:04.489Z","description":"AWS released Strands Box, an open-source sandbox for AI agents that combines OS-level isolation with Dogwood, a new policy language and evaluation engine that...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7b47890610cb68116f67c4ba87070631?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7b47890610cb68116f67c4ba87070631?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"aws,ai-agents,ai-security","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"AWS releases Strands Box, an open-source sandbox that limits AI agents based on what they've already done"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/aws-releases-strands-box-an-open-source-sandbox-that-limits-ai-agents-based-on-what-they-ve-already-aagpzkql2#faq","mainEntity":[{"@type":"Question","name":"What is AWS Strands Box and how is it different from a regular container sandbox for AI agents?","acceptedAnswer":{"@type":"Answer","text":"Strands Box is an open-source sandbox for AI agents that pairs OS-level isolation with Dogwood, a policy language and evaluation engine tracking an agent's prior actions. Unlike containers or microVMs, which isolate an agent without memory of its history, Box applies deterministic rules based on what the agent already did, such as rate-limiting Slack posts or capping API spend. Developers evaluating agent sandboxing options can follow releases like this one on daily.dev."}},{"@type":"Question","name":"What platforms does AWS Strands Box support right now?","acceptedAnswer":{"@type":"Answer","text":"The developer preview, released October 7 under the Apache 2.0 license, only supports Macs with Apple silicon running macOS 15 or later. AWS plans to add Linux and Windows support along with deployment targets including Bedrock AgentCore, ECS, and Kubernetes, but has not given a timeline for these additions. Teams planning agent infrastructure rollouts can track platform support updates via daily.dev."}},{"@type":"Question","name":"Does AWS Strands Box replace the need for IAM and access controls when running AI agents?","acceptedAnswer":{"@type":"Answer","text":"No, Strands Box does not replace IAM, monitoring, or human oversight. Analysts note it fills a real gap in agent security by applying history-aware, deterministic rules, but developers still must configure access correctly themselves, and the sandbox adds trusted components outside the isolation boundary along with some performance overhead. Engineers weighing agent security trade-offs can keep up with analyst takes through daily.dev."}}]}
```

