Docker Submitted AI Sandbox Specification to CNCF
The open-source specification aims to standardize agent permissions and portability across runtime environments.
Updated on Oct. 2, 2026 in Artificial Intelligence

Live Poll
Should the software industry adopt standardized permission rules for AI agents?
Docker has submitted the version 3 Sandbox Kit Specification to the Cloud Native Computing Foundation (CNCF), introducing a standardized way to package AI agents alongside their necessary permissions. Developed with industry partners, the specification is currently being implemented via Docker Sandboxes.
Why it matters
By defining a common format for agent requirements, the specification aims to prevent fragmentation in how runtime vendors handle permissions. It is intended to make AI agent access rights as portable as the agent workloads themselves.
The specification, licensed under Apache 2.0, utilizes Open Container Initiative (OCI) images to bundle AI agents with their specific requirements. This package includes a typed list of requested host resources, security credentials, and storage volumes.
The players
Docker
A software company focused on containerization tools that enable developers to build, share, and run applications in isolated environments.
Cloud Native Computing Foundation (CNCF)
A Linux Foundation project that maintains and supports a portfolio of open-source projects including Kubernetes for cloud-native computing.
AWS
A leading provider of cloud infrastructure services that co-developed the new specification.
The details
The technology functions by combining an AI agent workload with a set of ordered 'mixin' overlays—modular configuration layers that modify the container environment based on a dependency graph. By packaging tools and permission scopes into an OCI image—a standard format for containerized software—the specification ensures that an agent's access requests remain consistent regardless of the underlying runtime environment.
Timeline
September 24, 2026: Docker announced the specification submission at the WeAreDevelopers conference.
October 2, 2026: Official publication of the news.
The Tech Race
This submission mirrors the earlier industry-wide effort to standardize the Container Runtime Interface, which enabled interoperability across container engines. By moving the Sandbox Kit Specification to the CNCF, Docker aims to avoid the fragmentation that occurred in the early days of container orchestration.
Developers using Docker Sandboxes can now leverage the version 3 specification to manage agent permissions within their existing container workflows. The project currently relies on OCI-compliant infrastructure, meaning users will need to ensure their runtime supports these specific image structures.
The takeaway
The move toward open-source permission standards suggests that portable AI agents will soon become a baseline requirement for enterprise container security. Readers should watch for updates from the CNCF regarding the formal integration of the specification into the broader cloud-native ecosystem.
Further reading
For broader trends in infrastructure for machine learning, explore our Artificial Intelligence section.
Source note: This article includes information reported by InfoQ.
Live Poll
Should the software industry adopt standardized permission rules for AI agents?









