Back www.infoworld.com Aws Takes Aim At Runaway Ai Agent Behavior With Strands Box
Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on behavior, seeking to address security risks as enterprises give autonomous systems greater access to applications and data.
The tool, called Strands Box, combines operating system-level isolation with policies that govern what agents can do. Released in developer preview on October 7 under the Apache 2.0 license, it currently supports Macs with Apple silicon processors running macOS 15 or later.
Strands Box uses Dogwood, an open-source policy language developed by AWS, and its accompanying evaluation engine to determine whether an agent should be permitted to perform an action. The engine can factor in an agent’s recorded activity across different tools, allowing a file read through a shell command, for example, to trigger restrictions on subsequent network requests.
“Consider an agent investigating a production incident,” AWS said in a post. “We want it to post progress updates to the incident channel in Slack as it finds things, but not to flood the channel and bury the updates from humans. A policy can let the agent post, but no more than three times every 10 minutes. The agent can keep investigating, while Box enforces the posting limit without relying on the agent to remember it.”
Strands Box checks actions routed through its shell and Python interpreters and its Model Context Protocol (MCP) broker. By default, its network gateway evaluates outbound requests against policies and can attach credentials to approved requests without exposing the secrets to the agent.
AWS said the approach is intended to provide controls independent of the AI agent framework, reducing reliance on permission mechanisms built into individual agents. Its real strength, however, may lie less in the underlying technology than in how it is applied.
“Strands Box addresses a real security gap, although its underlying technologies are not new,” said Pareekh Jain , CEO of Pareekh Consulting. “Its main advantage is making security easier to enforce consistently across different AI agent frameworks.”
Security gains come with trade-offs
Dogwood’s policies do not cover every action an agent can take. Files accessed directly through an agent harness’s built-in tools, for instance, remain subject to operating system-level restrictions but are not evaluated by Dogwood’s policy engine.
AWS also acknowledged that its shell and Python interpreters run outside the sandbox as part of a trusted process, expanding the number of components whose security the system depends on.
Jain cautioned that the additional security controls could increase processing overhead and introduce new components that might themselves contain vulnerabilities.
“Poorly designed policies could block legitimate agent actions or create operational complexity, while overly permissive policies could still leave gaps,” said Tulika Sheel , senior vice president at Kadence International.
“It cannot prevent every harmful decision an agent makes within its allowed permissions,” Jain said. “Enterprises will still need IAM, monitoring, and human oversight.”
Strands Box faces a portability test
AWS said it wants to expand support beyond macOS and enable developers to deploy agents with their policies intact across platforms such as Amazon Bedrock AgentCore, Amazon ECS, and Kubernetes. The company has not provided a timeline for those capabilities.
Jain said a common policy layer could let developers concentrate on building agents while security teams maintain common rules. Adoption would depend on broader platform support and how much overhead policy enforcement introduces, he added.
Sheel said the open-source approach could help adoption, but enterprises would need evidence that the controls work reliably in production before adopting them widely.
“As agents become more autonomous, behavioral controls could become as fundamental to AI infrastructure as identity and access management are today,” Sheel said.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
