# How Chainguard Uses Hardware-Virtualized Sandboxes to Isolate AI Agents and Untrusted Code

DevFeed: [How Chainguard Uses Hardware-Virtualized Sandboxes to Isolate AI Agents and Untrusted Code](<https://devfeed.tech/articles/this-shit-is-hard-how-chainguard-is-sandboxing-athena-13283.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-how-chainguard-is-sandboxing-athena>)

Published: 2026-07-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [code](<https://devfeed.tech/tags/code.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [kvm](<https://devfeed.tech/tags/kvm.md>), [sandboxes](<https://devfeed.tech/tags/sandboxes.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

Chainguard describes applying its build-isolation approach to sandboxing AI agents and other untrusted code. The approach uses fresh hardware-virtualized QEMU/KVM environments with their own kernels to limit blast radius and prevent persistence or access to sensitive signing materials.

## Source excerpt

AI agents need sandboxes. Learn how Chainguard uses microVMs to safely run untrusted code, contain exploits, and protect sensitive workloads.