AI Dictionary › Fondamenti AI
A sandbox is an isolated environment for running code or testing behavior without letting any damage spread to the real system. Like the children's sandbox it is named after, it marks out a space for free experimentation: whatever happens stays within the borders. It is a central concept in both computer security and software development.
A sandbox is an isolated environment for running code or testing behavior without letting any damage spread to the real system. Like the children's sandbox it is named after, it marks out a space for free experimentation: whatever happens stays within the borders. It is a central concept in both computer security and software development.
Isolation is achieved by limiting what the code can touch: a restricted file system, blocked or filtered network, capped memory and CPU, controlled system calls. Techniques range from virtual machines to containers to operating system mechanisms such as seccomp on Linux. If the sandboxed code turns out to be malicious or broken, you destroy the environment and start fresh.
In AI, sandboxes have become essential: agents that write and execute code do so in isolated environments, LLM tools run with minimal permissions, and red teams probe models in confined spaces. The European AI Act also introduces regulatory sandboxes, supervised spaces where companies can trial AI systems under authority oversight. Outside AI, browsers isolate each tab and antivirus software detonates suspicious files in sandboxes.
The sandbox metaphor had circulated in software for decades, but the technical term took hold in the 1990s: the 1993 paper by Wahbe and colleagues on software-based fault isolation used sandboxing, and in 1995 the Java sandbox became the first mass-market example, confining applets downloaded from the web.
Una sandbox è un ambiente isolato in cui eseguire codice o testare comportamenti senza che eventuali danni si propaghino al sistema reale. Come la sabbiera dei bambini da cui prende il nome, delimita uno spazio dove si può sperimentare liberamente: qualunque cosa succeda, resta dentro i bordi. È un concetto centrale sia per la sicurezza informatica sia per lo sviluppo software.
L'isolamento si ottiene limitando ciò che il codice può toccare: file system ristretto, rete bloccata o filtrata, memoria e CPU contingentate, chiamate di sistema controllate. Le tecniche spaziano dalle macchine virtuali ai container fino ai meccanismi del sistema operativo come seccomp su Linux. Se il codice nella sandbox si rivela malevolo o difettoso, si distrugge l'ambiente e si riparte puliti.
Nell'AI le sandbox sono diventate essenziali: gli agenti che scrivono ed eseguono codice lo fanno in ambienti isolati, i tool degli LLM girano con permessi minimi e i team di red teaming testano i modelli in spazi confinati. L'AI Act europeo prevede inoltre le sandbox regolamentari, spazi controllati dove le aziende sperimentano sistemi AI sotto supervisione delle autorità. Fuori dall'AI, i browser isolano ogni scheda e gli antivirus fanno detonare i file sospetti in sandbox.
La metafora della sabbiera circolava nel software già da decenni, ma il termine tecnico si affermò negli anni '90: il paper del 1993 di Wahbe e colleghi sull'isolamento software usava sandboxing, e nel 1995 la sandbox Java divenne il primo esempio di massa, confinando gli applet scaricati dal web.
From our network
AGORÀ Intelligence — Enterprise AI Governance Platform
Govern AI at scale: policies, adoption and measurable results on your data. Built for boards and C-suite.
Visit agora-intelligence.com →From the Agora Intelligence blog
📱 Download the Android app (beta) iOS coming soon
Say what you mean. Get what you need.
Grace Certified — the AI coach that trains and certifies your prompt engineering — by Agora Intelligence.