<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw" -->

---
title: AWS takes aim at runaway AI agent behavior with Strands Box
description: AWS released Strands Box, an open-source sandbox for AI agents that uses operating system-level isolation combined with a policy language called Dogwood to...
canonical: https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AWS takes aim at runaway AI agent behavior with Strands Box | daily.dev
og:description: AWS released Strands Box, an open-source sandbox for AI agents that uses operating system-level isolation combined with a policy language called Dogwood to...
og:url: https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw
og:image: https://api.daily.dev/og/posts/Hkd4Xjdxw.png
og:image:alt: AWS takes aim at runaway AI agent behavior with Strands Box
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS takes aim at runaway AI agent behavior with Strands Box

**[InfoWorld](https://daily.dev/sources/infoworld)** · 4 min read · 0 upvotes · 0 comments

## Summary

AWS released Strands Box, an open-source sandbox for AI agents that uses operating system-level isolation combined with a policy language called Dogwood to restrict agent actions based on prior behavior. In developer preview since October 7 under Apache 2.0, it currently only supports Macs with Apple silicon on macOS 15+. The tool evaluates shell, Python, and MCP broker actions, and can rate-limit or condition permissions based on an agent's recorded activity. Analysts note it addresses a real security gap but has trade-offs: it excludes agent-harness built-in tool actions, expands the trusted code surface via its shell and Python interpreters, and may add processing overhead. AWS plans to expand platform support beyond macOS to Bedrock AgentCore, ECS, and Kubernetes, but has no timeline.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoworld.com/article/4232439/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box.html>

## Questions this post answers

### What is AWS Strands Box and what does it do for AI agent security?

Strands Box is an open-source sandbox released by AWS in developer preview on October 7 under the Apache 2.0 license, combining operating system-level isolation with a policy language called Dogwood to restrict what AI agents can do based on recorded behavior. It evaluates actions routed through its shell interpreter, Python interpreter, and Model Context Protocol broker, and its network gateway can attach credentials to approved requests without exposing secrets to the agent.

_Developers tightening agent permissions can track new sandboxing tools like this one via daily.dev._

### Does AWS Strands Box work on Windows or Linux?

Not yet. Strands Box currently only supports Macs with Apple silicon processors running macOS 15 or later, since it was released as a developer preview. AWS has stated it wants to expand support beyond macOS and let developers deploy agents with their policies intact across platforms like Amazon Bedrock AgentCore, Amazon ECS, and Kubernetes, but it has not given a timeline for that expansion.

_Teams evaluating cross-platform agent sandboxing can follow this rollout on daily.dev._

### What are the limitations of policy-based sandboxing for AI agents like Strands Box?

Dogwood's policies do not cover every agent action: files accessed directly through an agent harness's built-in tools remain subject only to operating system-level restrictions, bypassing the policy engine. Additionally, Strands Box's own shell and Python interpreters run outside the sandbox as a trusted process, expanding the code base that must be secure. Experts warn this adds processing overhead and new components that could themselves introduce vulnerabilities, so enterprises still need IAM, monitoring, and human oversight.

_Security engineers weighing agent sandbox trade-offs can keep up with analyses like this on daily.dev._

## Similar posts on daily.dev

- [AWS creates a sandbox for its agent experiments](https://daily.dev/posts/aws-creates-a-sandbox-for-its-agent-experiments-r5p1skjmm) · The New Stack · 0 upvotes · 0 comments

---

Tags: [#aws](https://daily.dev/tags/aws), [#ai-agents](https://daily.dev/tags/ai-agents), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AWS takes aim at runaway AI agent behavior with Strands Box","url":"https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw"},"datePublished":"2026-10-08T10:15:40.753Z","dateModified":"2026-10-08T14:36:51.889Z","description":"AWS released Strands Box, an open-source sandbox for AI agents that uses operating system-level isolation combined with a policy language called Dogwood to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1dc284e9ba641eec9fb1b594c77bc318?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1dc284e9ba641eec9fb1b594c77bc318?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoWorld","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoWorld","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/bf6d68a999064029b0bb09aa6268f1f3","url":"https://daily.dev/sources/infoworld"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"aws,ai-agents,mcp","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoWorld","item":"https://daily.dev/sources/infoworld"},{"@type":"ListItem","position":3,"name":"AWS takes aim at runaway AI agent behavior with Strands Box"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box-hkd4xjdxw#faq","mainEntity":[{"@type":"Question","name":"What is AWS Strands Box and what does it do for AI agent security?","acceptedAnswer":{"@type":"Answer","text":"Strands Box is an open-source sandbox released by AWS in developer preview on October 7 under the Apache 2.0 license, combining operating system-level isolation with a policy language called Dogwood to restrict what AI agents can do based on recorded behavior. It evaluates actions routed through its shell interpreter, Python interpreter, and Model Context Protocol broker, and its network gateway can attach credentials to approved requests without exposing secrets to the agent. Developers tightening agent permissions can track new sandboxing tools like this one via daily.dev."}},{"@type":"Question","name":"Does AWS Strands Box work on Windows or Linux?","acceptedAnswer":{"@type":"Answer","text":"Not yet. Strands Box currently only supports Macs with Apple silicon processors running macOS 15 or later, since it was released as a developer preview. AWS has stated it wants to expand support beyond macOS and let developers deploy agents with their policies intact across platforms like Amazon Bedrock AgentCore, Amazon ECS, and Kubernetes, but it has not given a timeline for that expansion. Teams evaluating cross-platform agent sandboxing can follow this rollout on daily.dev."}},{"@type":"Question","name":"What are the limitations of policy-based sandboxing for AI agents like Strands Box?","acceptedAnswer":{"@type":"Answer","text":"Dogwood's policies do not cover every agent action: files accessed directly through an agent harness's built-in tools remain subject only to operating system-level restrictions, bypassing the policy engine. Additionally, Strands Box's own shell and Python interpreters run outside the sandbox as a trusted process, expanding the code base that must be secure. Experts warn this adds processing overhead and new components that could themselves introduce vulnerabilities, so enterprises still need IAM, monitoring, and human oversight. Security engineers weighing agent sandbox trade-offs can keep up with analyses like this on daily.dev."}}]}
```

