< Back to situation

[REVISION HISTORY]

Cloud sandboxing developments for AI agent security

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-26 04:01 UTC → 2026-10-07 20:21 UTC · added removed

Major technology providers are introducing specialized sandboxing solutions to address security vulnerabilities associated with AI agents. Microsoft released Azure Container Apps Sandboxes, which utilize hardware-isolated microVMs with individual Linux kernels to run untrusted code. This service allows users to manage egress policies through an external proxy to prevent unauthorized data transmission. The release follows research demonstrating how AI agents can use artifact registries as bidirectional covert channels to exfiltrate data. Following this, Docker launched Cloud Sandboxes, applying microVM architecture to cloud infrastructure to provide hardware-level isolation. Docker noted that traditional containers were not designed for the isolation levels required by AI agents that may attempt to probe or mutate their environments. Alongside this service, Docker introduced the Kits specification (v3), an open standard for packaging AI agent sandboxes as OCI-compliant images, and has committed to submitting the specification to the Cloud Native Computing Foundation for neutral governance. Expanding its security offerings, Microsoft unveiled Microsoft Execution Containers (MXC) at the Build 2026 conference. MXC is a policy-driven SDK designed to manage and restrict AI agent access to files and networks. Utilizing a ‘composable sandbox’ approach, the toolkit provides varying levels of isolation, including process, session, and MicroVM levels, enforced by the operating system kernel. MXC supports Windows, macOS, Linux, and the Windows Subsystem for Linux (WSL). Early adopters include GitHub Copilot and OpenClaw, with partners such as NVIDIA, Anthropic, and OpenAI expected to utilize the technology for enterprise-level rule enforcement.

Versions

  1. 2026-10-07 20:21 UTC Cloud sandboxing developments for AI agent security
  2. 2026-09-26 04:01 UTC Cloud sandboxing developments for AI agent security

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.