Janakiram MSV recently wrote an intriguing piece in The New Stack examining how AWS, Microsoft, Google Cloud, and Cloudflare have each approached AI code sandboxes. His article does an excellent job highlighting the different architectural decisions each platform has made. While the implementations vary, what stood out to us wasn’t how each company built its sandbox—it was the fact that all four concluded they needed one.
That convergence may be the most important takeaway. Not because AI code sandboxes are the end state, but because they signal something much broader: enterprise infrastructure is beginning to evolve around a new architectural principle.
For several years, Replica has argued that certain categories of high-risk digital work deserve purpose-built execution environments rather than additional controls layered onto trusted infrastructure. We didn’t arrive at that conclusion because of AI. We arrived there by watching threat researchers, malware analysts, fraud investigators, innovation teams, and security engineers increasingly perform uncertain work inside environments designed for trusted work. AI has simply made that architectural mismatch much more visible.
Viewed through that lens, the recent wave of AI code sandboxes isn’t just another product category. It’s evidence that the industry is beginning to move in the same direction.
Looking Beyond the Sandbox
Janakiram’s article focuses on how each provider approached AI code sandboxes, and those implementation differences are genuinely interesting.
What caught our attention, however, was something else entirely.
Despite taking different technical approaches, AWS, Microsoft, Google Cloud, and Cloudflare all reached the same architectural conclusion: there are categories of work that shouldn’t simply run alongside traditional enterprise workloads. That convergence may be the most important part of the story because it suggests AI code sandboxes aren’t just another feature being added to cloud platforms. They’re evidence that enterprise infrastructure itself is beginning to evolve.
AI Didn’t Create the Problem. It Made It Impossible to Ignore.
It’s easy to think of AI code sandboxes as a response to generative AI, but that overlooks a much broader trend.
Organizations have been performing uncertain digital work for years. Threat researchers visit unknown websites every day. Malware analysts intentionally execute malicious code. Fraud teams investigate suspicious content. Security engineers evaluate unfamiliar software before approving it for production. Innovation teams experiment with emerging technologies whose behavior isn’t yet fully understood.
None of those activities fit neatly inside infrastructure designed for trusted work.
AI simply accelerated the conversation. Once AI agents began generating and executing code autonomously, the need for dedicated execution environments became obvious. But the underlying architectural challenge has existed for much longer. AI didn’t create the problem…it made it impossible to ignore.
A Different Architectural Assumption
For decades, enterprise security has operated under a consistent assumption: high-risk work would take place on trusted infrastructure, protected by increasingly sophisticated layers of security controls. Identity systems verify who you are. Endpoint protection monitors the device. Firewalls and Zero Trust architectures restrict access. Cloud security platforms enforce policy. Governance solutions define what users are allowed to do.
Those investments have fundamentally improved enterprise security, and nothing about the emergence of AI changes their importance.
What AI does change is the nature of the work itself. As organizations begin asking employees—and increasingly AI agents—to execute code, analyze unfamiliar content, evaluate third-party software, and interact with systems that haven’t yet earned trust, the challenge shifts. It’s no longer just about controlling access to trusted infrastructure. It’s about recognizing that not every workload belongs there in the first place.
That’s an architectural shift, not simply another security control.
Protection and Containment
Traditional security investments focus on reducing the likelihood of a bad outcome, while containment focuses on reducing the consequences when uncertainty is unavoidable. Those ideas don’t compete—they complement one another.
The emergence of AI code sandboxes suggests the industry increasingly recognizes that isolation isn’t simply another security feature. It’s becoming part of the infrastructure required to safely execute uncertain work.
What Comes Next
If this trend continues, organizations may eventually think about execution environments the same way they think about identity, networking, or cloud platforms today—not as isolated features, but as foundational infrastructure. We’ve seen similar architectural shifts before. Containers changed how applications are deployed. Zero Trust changed how organizations think about access. Cloud transformed where workloads run. Each represented a fundamental change in how enterprises approached computing, not simply another product category.
The next evolution may be centered on where uncertain work belongs. As organizations increasingly interact with unpredictable code, content, systems, and AI agents, dedicated execution environments may become just as foundational as the infrastructure layers that came before them.
To learn more about Replica Cyber, and how we’re helping organizations around the world innovate safely, drop us a line.

