# Cloud sandboxing developments for AI agent security

> Live situation record from CLSTR: https://clstr.news/situations/cloud-sandboxing-developments-for-ai-agent-security
> Updated: 2026-10-07T17:19:47.000Z. Sources: 9. Developments: 3.

Major technology providers are introducing specialized sandboxing solutions to address security vulnerabilities associated with AI agents.

Microsoft released Azure Container Apps Sandboxes, which utilize hardware-isolated microVMs with individual Linux kernels to run untrusted code. This service allows users to manage egress policies through an external proxy to prevent unauthorized data transmission. The release follows research demonstrating how AI agents can use artifact registries as bidirectional covert channels to exfiltrate data.

Following this, Docker launched Cloud Sandboxes, applying microVM architecture to cloud infrastructure to provide hardware-level isolation. Docker noted that traditional containers were not designed for the isolation levels required by AI agents that may attempt to probe or mutate their environments. Alongside this service, Docker introduced the Kits specification (v3), an open standard for packaging AI agent sandboxes as OCI-compliant images, and has committed to submitting the specification to the Cloud Native Computing Foundation for neutral governance.

Expanding its security offerings, Microsoft unveiled Microsoft Execution Containers (MXC) at the Build 2026 conference. MXC is a policy-driven SDK designed to manage and restrict AI agent access to files and networks. Utilizing a ‘composable sandbox’ approach, the toolkit provides varying levels of isolation, including process, session, and MicroVM levels, enforced by the operating system kernel. MXC supports Windows, macOS, Linux, and the Windows Subsystem for Linux (WSL). Early adopters include GitHub Copilot and OpenClaw, with partners such as NVIDIA, Anthropic, and OpenAI expected to utilize the technology for enterprise-level rule enforcement.

## Timeline

### 2026-10-07: Microsoft launches Execution Containers to secure AI agents

Microsoft has launched Microsoft Execution Containers (MXC), a security SDK that uses sandboxing to restrict AI agents' access to sensitive data and system resources at the operating system level.

5 sources. https://clstr.news/cluster/microsoft-launches-execution-containers-to-secure-ai-agents

### 2026-09-24: Docker launches Cloud Sandboxes to secure AI agents

Docker has introduced Cloud Sandboxes, utilizing microVM architecture to provide secure, isolated environments for AI agents to prevent unauthorized access to host systems.

2 sources. https://clstr.news/cluster/docker-launches-cloud-sandboxes-to-secure-ai-agents

### 2026-09-23: Azure Container Apps Sandboxes released to secure untrusted AI agent code

Azure Container Apps Sandboxes are now generally available to isolate untrusted AI agent code, addressing security risks like covert data channels through artifact registries.

2 sources. https://clstr.news/cluster/azure-container-apps-sandboxes-released-to-secure-untrusted-ai-agent-code

---
Cite as: Cloud sandboxing developments for AI agent security. CLSTR, https://clstr.news/situations/cloud-sandboxing-developments-for-ai-agent-security
