{"id":9951,"date":"2026-10-08T10:17:15","date_gmt":"2026-10-08T10:17:15","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9951"},"modified":"2026-10-08T10:17:15","modified_gmt":"2026-10-08T10:17:15","slug":"aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9951","title":{"rendered":"AWS takes aim at runaway AI agent behavior with Strands Box"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column \">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, seeking to address security risks as enterprises give autonomous systems greater access to applications and data.<\/p>\n<p class=\"wp-block-paragraph\">The tool, called Strands Box, combines <a href=\"https:\/\/www.infoworld.com\/article\/4215416\/running-ai-agents-in-sandboxes-with-microsoft-execution-containers.html\" target=\"_blank\" rel=\"noopener\">operating system-level isolation<\/a> with policies that govern what agents can do. Released in developer preview on October 7 under the Apache 2.0 license, it currently supports Macs with Apple silicon processors running macOS 15 or later.<\/p>\n<p class=\"wp-block-paragraph\">Strands Box uses Dogwood, an open-source policy language developed by AWS, and its accompanying evaluation engine to determine whether an agent should be permitted to perform an action. The engine can factor in an agent\u2019s recorded activity across different tools, allowing a file read through a shell command, for example, to trigger restrictions on subsequent network requests.<\/p>\n<p class=\"wp-block-paragraph\">\u201cConsider an agent investigating a production incident,\u201d AWS said in a post. \u201cWe want it to post progress updates to the incident channel in Slack as it finds things, but not to flood the channel and bury the updates from humans. A policy can let the agent post, but no more than three times every 10 minutes. The agent can keep investigating, while Box enforces the posting limit without relying on the agent to remember it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Strands Box checks actions routed through its shell and Python interpreters and its <a href=\"https:\/\/www.infoworld.com\/article\/4028404\/why-mcp-matters-and-how-to-secure-it.html\">Model Context Protocol (MCP)<\/a> broker. By default, its network gateway evaluates outbound requests against policies and can attach credentials to approved requests without exposing the secrets to the agent.<\/p>\n<p class=\"wp-block-paragraph\">AWS said the approach is intended to provide controls <a href=\"https:\/\/www.infoworld.com\/article\/4175859\/microsofts-open-source-toolkit-for-controlling-out-of-control-ai-agents.html\">independent of the AI agent<\/a> framework, reducing reliance on permission mechanisms built into individual agents. Its real strength, however, may lie less in the underlying technology than in how it is applied.<\/p>\n<p class=\"wp-block-paragraph\">\u201cStrands Box addresses a real security gap, although its underlying technologies are not new,\u201d said <a href=\"https:\/\/pareekh.com\/about\/\" target=\"_blank\" rel=\"noopener\">Pareekh Jain<\/a>, CEO of Pareekh Consulting. \u201cIts main advantage is making security easier to enforce consistently across different AI agent frameworks.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Security gains come with trade-offs<\/h2>\n<p class=\"wp-block-paragraph\">Dogwood\u2019s policies do not cover every action an agent can take. Files accessed directly through an agent harness\u2019s built-in tools, for instance, remain subject to operating system-level restrictions but are not evaluated by Dogwood\u2019s policy engine.<\/p>\n<p class=\"wp-block-paragraph\">AWS also acknowledged that its shell and Python interpreters run outside the sandbox as part of a trusted process, expanding the number of components whose security the system depends on.<\/p>\n<p class=\"wp-block-paragraph\">Jain cautioned that the additional security controls could increase processing overhead and introduce new components that might themselves contain vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">\u201cPoorly designed policies could block legitimate agent actions or create operational complexity, while overly permissive policies could still leave gaps,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/tulikasheel\/\" target=\"_blank\" rel=\"noopener\">Tulika Sheel<\/a>, senior vice president at Kadence International.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt cannot prevent every harmful decision an agent makes within its allowed permissions,\u201d Jain said. \u201cEnterprises will still need IAM, monitoring, and human oversight.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Strands Box faces a portability test<\/h2>\n<p class=\"wp-block-paragraph\">AWS said it wants to expand support beyond macOS and enable developers to deploy agents with their policies intact across platforms such as Amazon Bedrock AgentCore, Amazon ECS, and Kubernetes. The company has not provided a timeline for those capabilities.<\/p>\n<p class=\"wp-block-paragraph\">Jain said a common policy layer could let developers concentrate on building agents while security teams maintain common rules. Adoption would depend on broader platform support and how much overhead policy enforcement introduces, he added.<\/p>\n<p class=\"wp-block-paragraph\">Sheel said the open-source approach could help adoption, but enterprises would need evidence that the controls work reliably in production before adopting them widely.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAs agents become more autonomous, behavioral controls could become as fundamental to AI infrastructure as identity and access management are today,\u201d Sheel said.<\/p>\n<p class=\"wp-block-paragraph\"><em>The article originally appeared on <a href=\"https:\/\/www.infoworld.com\/article\/4232439\/aws-takes-aim-at-runaway-ai-agent-behavior-with-strands-box.html\">InfoWorld<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, seeking to address security risks as enterprises give autonomous systems greater access to applications and data. The tool, called Strands Box, combines operating system-level isolation with policies that govern what agents can [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9952,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9951","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9951"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9951"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9951\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9952"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9951"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}