The Hallway Track
Engineering Insights

How we contain Claude across products

Simon Willison · May 30, 2026 · Engineering Insights

Anthropic published detailed documentation of how it sandboxes Claude agents across its products.

“if credentials never enter the sandbox, they can't be exfiltrated, regardless of whether the cause is a user, a model finding a “creative” path, or an attacker.”

Anthropic released a detailed overview of the sandboxing techniques it uses to contain Claude agents across Claude.ai (gVisor), Claude Code (Seatbelt/Bubblewrap), and Cowork (full VMs), spanning process sandboxes, filesystem boundaries, and egress controls. It matters because agent security and exfiltration risks are a growing concern, and transparent documentation lets engineers evaluate how much to trust agentic AI products.

sandboxing ai-agents security anthropic

Watch / read the original source →