AWS Launches Strands Box to Restrict Runaway AI Agent Behaviour
Share
Amazon Web Services (AWS) has launched Strands Box, an open-source sandbox designed to mitigate security risks associated with autonomous AI agents. The tool allows developers to restrict agent actions based on historical behaviour, addressing concerns over “runaway” systems as enterprises grant AI greater access to sensitive applications and data.
Released in developer preview under the Apache 2.0 license, Strands Box currently supports Macs equipped with Apple silicon running macOS 15 or later. The system integrates operating system-level isolation with specific security policies to govern what an autonomous agent can and cannot execute.
Policy-Based Control with Dogwood
At the core of Strands Box is Dogwood, a new open-source policy language developed by AWS. The accompanying evaluation engine allows security teams to set rules based on an agent’s cumulative activity. For example, a policy could permit an agent to read files via a shell command but subsequently restrict its ability to make network requests based on that specific action.
AWS highlighted a practical use case involving incident response. While an agent might be authorised to post updates to a communication channel like Slack, a Dogwood policy can enforce a limit—such as no more than three posts every 10 minutes—to prevent the agent from flooding the channel and obscuring human communication. This enforcement happens at the infrastructure level, meaning the agent does not need to self-regulate its permissions.
Securing the AI Environment
The sandbox monitors actions routed through its Python and shell interpreters, as well as its Model Context Protocol (MCP) broker. A dedicated network gateway evaluates outbound requests and can securely attach credentials to approved traffic without exposing sensitive secrets directly to the AI agent.
By decoupling security controls from the AI agent framework itself, AWS aims to provide a consistent enforcement layer that does not rely on the internal permission mechanisms of various third-party models. However, the system is not without limitations. Certain file accesses made through an agent’s built-in tools may bypass the Dogwood engine, remaining subject only to standard operating system restrictions.
Implementation and Future Support
Security analysts note that while the underlying technologies within Strands Box are established, the tool’s primary value lies in its ability to centralise security enforcement across diverse AI frameworks. Experts caution that adding these layers may introduce processing overhead and that poorly configured policies could inadvertently block legitimate operations.
AWS intends to expand Strands Box support beyond macOS to include platforms such as Amazon Bedrock, Amazon ECS, and Kubernetes. While a specific timeline for these updates has not been disclosed, the open-source approach is expected to encourage broader enterprise adoption as organisations seek to standardise AI security and governance. Despite these new controls, AWS maintained that enterprises still require robust identity and access management (IAM) and human oversight to manage autonomous systems effectively.




Leave a Reply