Amazon Web Services has released an open-source sandbox that lets developers restrict AI agent actions based on their previous behavior, addressing security concerns as companies grant autonomous systems broader access to applications and data. The tool, called Strands Box, was launched in developer preview on October 7 under the Apache 2.0 license, according to a report published by CSO Online. The system merges operating system-level isolation with policies that control what agents can execute, aiming to provide safeguards independent of individual AI agent frameworks.
Strands Box currently supports only Macs with Apple silicon processors running macOS 15 or later. The tool uses Dogwood, an open-source policy language developed by AWS, along with its evaluation engine to decide whether an agent should be allowed to perform a specific action. The engine can consider an agent's recorded activity across different tools, enabling a file read through a shell command to trigger limits on later network requests. The sandbox checks actions routed through its shell and Python interpreters and its Model Context Protocol broker, while its network gateway evaluates outbound requests against policies and can attach credentials to approved requests without revealing secrets to the agent.
AWS explained that the tool can enforce behavioral limits without relying on the agent itself, using the example of an agent investigating a production incident that posts updates to a Slack channel but must avoid flooding it. "A policy can let the agent post, but no more than three times every 10 minutes," the company stated. "The agent can keep investigating, while Box enforces the posting limit without relying on the agent to remember it." However, the report notes that Dogwood's policies don't cover every action an agent can take—files accessed directly through an agent harness's built-in tools remain subject to operating system restrictions but aren't evaluated by Dogwood's policy engine. AWS also acknowledged that its shell and Python interpreters run outside the sandbox as part of a trusted process, expanding the number of components the system's security depends on.
The report indicates that security gains come with trade-offs, as additional controls could increase processing overhead and introduce new components that might themselves harbor vulnerabilities. Pareekh Jain, CEO of Pareekh Consulting, told the publication that "its main advantage is making security easier to enforce consistently across different AI agent frameworks," while cautioning that "it cannot prevent every harmful decision an agent makes within its allowed permissions." Tulika Sheel, senior vice president at Kadence International, warned that "poorly designed policies could block legitimate agent actions or create operational complexity, while overly permissive policies could still leave gaps." Enterprises will still require identity and access management, monitoring, and human oversight alongside the sandbox, according to the report.
AWS stated it wants to expand support beyond macOS and enable developers to deploy agents with their policies intact across platforms including Amazon Bedrock AgentCore, Amazon ECS, and Kubernetes, though the company hasn't provided a timeline for those capabilities. The report notes that adoption would depend on broader platform support and how much overhead policy enforcement introduces. Sheel said enterprises would need evidence that the controls work reliably in production before adopting them widely, while noting that "as agents become more autonomous, behavioral controls could become as fundamental to AI infrastructure as identity and access management are today." A common policy layer could let developers concentrate on building agents while security teams maintain uniform rules, according to Jain. The open-source approach raises questions about whether enterprises will prioritize developer flexibility over centralized control, particularly as policy complexity grows alongside agent capabilities.

