# What Docker announced
Docker introduced an open Sandbox Kit specification that packages an AI agent, its tools and the access it requests as OCI images. The spec is published under the Apache 2.0 license and is intended as a common format that sandbox runtimes and developers can use to describe the environment and authorities an agent needs.
# Why this matters
AI agents act differently than conventional workloads: they may install dependencies, run code, call external services and probe their environment to find capabilities they can use. That behavior makes it harder to rely on container boundaries alone. By declaring requested hosts, credentials, volumes and other capabilities inside the image, the Sandbox Kit format gives teams a way to review and approve what an agent will be allowed to do before it runs.
# How the spec works in practice
- Kits are packaged as OCI images with descriptors that list network hosts, credentials, volumes and capabilities the agent or supporting component requests.
- Using OCI images lets teams build, store, sign and scan Kits with the same tooling they already use for containers.
- Pinning a Kit to an image digest ties the agent's code and its access declaration together, so any change in requested authority is visible during updates.
- Runtimes can gate updates that expand access, stopping them until reviewed and approved.
Docker President and COO Mark Cavage presented the specification at the WeAreDevelopers North America conference. He used a demo where an agent running in a container accessed a host secret by leveraging a mounted Docker socket. Cavage distinguished between containers (an execution mechanism) and containment (controls around what an agent is allowed to do), arguing that agents require explicit, reviewable declarations of authority rather than relying solely on container isolation.
# Adoption and governance plans
# Practical implications for teams
- Image signing and OCI scanning workflows apply directly to Sandbox Kits, enabling existing build-and-release controls to cover agents and tools.
- Pinning Kits by digest makes it easier to detect and block unauthorized expansions of access during updates.
# Short summary