Solutions  ·  2026-09-27

Docker launches Cloud Sandboxes — microVM-isolated AI agent execution plus next-gen OCI-based Kits (GA)

SolutionsHigh impactGlobal
On Sept 24, 2026 Docker announced Docker Cloud Sandboxes, extending its local sandbox isolation to Docker-managed cloud infrastructure: each agent runs in a dedicated microVM (custom VMM, hardware-level isolation) with an egress firewall, credential-injection proxy (agents never see raw host secrets), and boot in low hundreds of ms. Docker also published next-gen Kits — an open spec packaging an agent, tools, and access rules (network, credentials, mounts, MCP) as standard OCI images with deny-by-default semantics, committed for submission to the CNCF under Apache-2.0. Available today.
This is the container company explicitly saying containers aren't sufficient for AI-agent isolation and shipping a hardware-level boundary for unattended agents — a de-facto endorsement that runtime isolation plus portable, deny-by-default access rules is the baseline for agent security. Combined with the CNCF-bound OCI standard, it could shape how agent guardrails are packaged and distributed across the ecosystem, not just within Docker.
Platform/DevSecOps teams standardizing agent runtime isolation and repeatable guardrail packaging should evaluate Cloud Sandboxes and the Kits spec now; enterprises adopting OCI-based 'agent + guardrails' artifacts should track the CNCF submission for ecosystem-wide ports.
Docker launches Cloud Sandboxes (Business Insider/MarketWatch via GlobeNewswire)Docker's new sandboxes aim to contain AI agents (forkast.news)Docker brings sandboxes for AI agents to the cloud (techzine.eu)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →