AWS launches open-source AI agent sandbox to prevent YOLO mode disasters
Strands Box is the latest open source AI control tool from the cloud giant; like its predecessors, it promises tighter reins on autonomous agents
Amazon Web Services (AWS) has introduced a new open-source sandbox tool called Strands Box to help prevent autonomous AI agents from acting recklessly or without human oversight. The company has long advocated for responsible AI and has now expanded its open-source AI control toolbox to include this full-fledged solution.
According to AWS, many AI agents are increasingly operating in "YOLO mode," meaning they run without human review and approve every action themselves. While traditional sandboxes like containers and microVMs can isolate these agents, they lack the ability to enforce contextual rules. This means that even if a tool or resource is isolated, there's no guarantee the agent won't abuse it – for example, by deleting important data or connecting to the internet for malicious purposes.
To address this, Strands Box incorporates several key components. It uses OS-level isolation, along with AWS’ other open-source AI control tools, to maintain greater control over autonomous agents’ behavior. One of the core features is the Dogwood Local Engine, which provides temporal awareness to the policy engine in Box. This allows policies to check not only what an agent wants to do but also what it has done in the past.
For instance, an agent could be permitted to post status updates to Slack, but the policy could cap the frequency at three updates every ten minutes to prevent spamming. Additionally, Box can control when an agent performs Git pushes or limits API calls that might result in unexpected costs. The system also includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions more transparent for developers.
AWS VP and distinguished engineer Marc Brooker, co-creator of Dogwood and Strands Box, emphasized that these interpreters are crucial for making agentic behavior more understandable. By exposing operations like file deletions and API requests, developers can write more precise policies to prevent unwanted actions. Brooker stated that Box enforces these rules independently of the agents, ensuring they don't circumvent the set boundaries.
While AWS claims Box will prevent agents from running amok, it's important to note that developers still bear responsibility for granting access and determining when human review is necessary. Agent safety remains an area where the industry faces significant challenges, and AWS is committed to ongoing investment in this field, both within the AWS cloud and through open-source contributions.
Strands Box is currently available on GitHub for macOS, with Linux support in development and a Windows client "on our radar," though no release dates have been announced yet.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.