Amazon Web Services expanded its open-source AI control stack by introducing a new sandbox solution named Strands Box. The tool uses operating system-level isolation alongside recent open-source AI control utilities from AWS. The goal is to retain greater control over the behavior of autonomous artificial intelligence agents.
The AWS team stated that agents frequently run in YOLO mode by approving every action without human review. Standard containers and microVMs offer strong isolation, but they lack contextual rule enforcement. When an isolated agent accesses a tool, nothing stops it from deleting a production database or reaching the open internet.
Strands Box adds temporal awareness
Strands Box addresses this vulnerability by integrating the Dogwood Local Engine. This integration gives the policy engine temporal awareness. Tool calls are checked against what the agent wants to do and what it has already done.
AWS provided an example where an agent can post status updates to Slack. The system restricts the agent to a maximum of three posts every ten minutes to prevent spamming operators. An AWS spokesperson noted the box can control Git push actions or cap API calls that could incur massive costs.

Interpreters expose operations
The software package also includes Strands Shell and Monty for Python. These components expose shell and Python operations to the Dogwood policy engine and event history. This visibility makes agentic actions clearer to developers and helps policies account for agent intentions.
AWS VP and distinguished engineer Marc Brooker explained that the interpreters make agentic behavior more intelligible. Developers can write precise policies to stop agents from taking harmful actions. Brooker stated that Box enforces these rules deterministically without trusting agents to follow instructions.
Availability and next steps
Strands Box is available now on GitHub and supports any agent or harness. The current release is restricted to macOS. Linux support is currently in development. AWS reported that a Windows client is on its radar, though neither operating system has a planned release date. Future deployments are also planned for AgentCore, ECS, and Kubernetes.



