
What happened
Chock launched a sandbox-first AI coding harness that runs agents inside the OS's own sandbox on a throwaway copy, under an uneditable chock.zon policy, with every turn and tool call in an append-only, hash-chained session log.
Why it matters
Security and platform teams get attribution — which commits came from an agent — plus a log an auditor can verify without trusting the agent, and a sandbox that cannot be switched off.
What to watch
Attribution covers only sessions run under Chock, so its worth depends on rollout coverage; sealing is only as good as key custody. Chock is pre-alpha.
WHO IT HITSSecurity and platform teams at organizations where developers already run coding agents next to production credentials get a sandbox, policy, and audit trail they can hand to auditors. The log helps establish which commits came from an agent, with the rest human by elimination.
Summaries like this, in your inbox every morning.
Chock enters a landscape where coding agents already run commands, write files, and reach the network, often next to production credentials on developer machines. The harness's pitch is that most other harnesses ask the agent to be careful, while Chock puts what an agent may do outside the agent's control. Its policy file, chock.zon, sits in the project and can be read but not edited by the agent; if an action needs approval and nobody answers, it is refused.
The comparison table is based on reading source code, not documentation. It says ten harnesses were read, and the three that sandbox at all mount the whole filesystem into the sandbox, and none keeps a tamper-evident log. Chock's answer is an append-only, hash-chained log where each event carries the hash of the one before it, plus an organisation policy that projects can narrow but not widen.
The limits are explicit. Attribution is worth what rollout coverage is, sealing depends on key custody, and there is no remote attestation or hardware root of trust. Whether this changes how security teams admit agent sessions likely hinges on whether the remaining roadmap links — a signature on the commit and a forge attesting the push — ship, and on whether the log's tamper evidence holds up in an audit.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
OpenAI and Anthropic are reviewing tens of thousands of incidents in which their AI agents hacked websites, us…

Tamara Grant, who finished Purdue University's Master of Science in Artificial Intelligence in spring 2026, wa…

Zenity Labs published findings on September 24 detailing 'SalesBleed,' an attack chain that slipped hidden pro…

Palo Alto Networks announced Prisma AIRS runtime security integrated with Google Cloud's Agent Gateway, a Gemi…

Google, OpenAI, and Anthropic announced a joint move on AI safety

In five experiments with 3,132 participants, mere access to AI advice — including answers shown automatically…
