< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 9 sources · 15 days · First seen · Last updated

Cloud sandboxing developments for AI agent security

Overview

Major technology providers are introducing specialized sandboxing solutions to address security vulnerabilities associated with AI agents.

Microsoft released Azure Container Apps Sandboxes, which utilize hardware-isolated microVMs with individual Linux kernels to run untrusted code. This service allows users to manage egress policies through an external proxy to prevent unauthorized data transmission. The release follows research demonstrating how AI agents can use artifact registries as bidirectional covert channels to exfiltrate data.

Following this, Docker launched Cloud Sandboxes, applying microVM architecture to cloud infrastructure to provide hardware-level isolation. Docker noted that traditional containers were not designed for the isolation levels required by AI agents that may attempt to probe or mutate their environments. Alongside this service, Docker introduced the Kits specification (v3), an open standard for packaging AI agent sandboxes as OCI-compliant images, and has committed to submitting the specification to the Cloud Native Computing Foundation for neutral governance.

Expanding its security offerings, Microsoft unveiled Microsoft Execution Containers (MXC) at the Build 2026 conference. MXC is a policy-driven SDK designed to manage and restrict AI agent access to files and networks. Utilizing a ‘composable sandbox’ approach, the toolkit provides varying levels of isolation, including process, session, and MicroVM levels, enforced by the operating system kernel. MXC supports Windows, macOS, Linux, and the Windows Subsystem for Linux (WSL). Early adopters include GitHub Copilot and OpenClaw, with partners such as NVIDIA, Anthropic, and OpenAI expected to utilize the technology for enterprise-level rule enforcement.

Entities

OpenAI · Microsoft Azure · RubyGems · Docker · Nvidia

Timeline

  1. [TECHNOLOGY] 5 sources
    Microsoft launches Execution Containers to secure AI agents

    Microsoft has launched Microsoft Execution Containers (MXC), a security SDK that uses sandboxing to restrict AI agents' access to sensitive data and system resources at the operating system level.

  2. [TECHNOLOGY] 2 sources
    Docker launches Cloud Sandboxes to secure AI agents

    Docker has introduced Cloud Sandboxes, utilizing microVM architecture to provide secure, isolated environments for AI agents to prevent unauthorized access to host systems.

  3. [TECHNOLOGY] 2 sources
    Azure Container Apps Sandboxes released to secure untrusted AI agent code

    Azure Container Apps Sandboxes are now generally available to isolate untrusted AI agent code, addressing security risks like covert data channels through artifact registries.

Sources

365community.online · borncity.com · cryptobriefing.com · cybernoz.com · dev.to · games.yahoo.com.tw · gamestar.de · techblog.gr · theregister.co.uk

This summary has been updated 1 time: see revision history