
What happened
Benchling deployed Amazon Bedrock AgentCore Code Interpreter in VPC mode in early April 2026, and now processes more than 600 code execution sessions per day across more than 250 tenants per week with zero security incidents.
Why it matters
This gives life sciences researchers a way to run AI-generated scientific code across thousands of tenants without cross-tenant data leakage, a model other regulated industries may study.
What to watch
The architecture relies on continuous automated validation, so its resilience hinges on whether future infrastructure changes are caught by those tests.
WHO IT HITSEnterprise security and infrastructure teams running AI-generated code for regulated industries, such as life sciences researchers, can now see a tested blueprint that blocks DNS-based data exfiltration without building custom sandboxing.
Summaries like this, in your inbox every morning.
Benchling's security team found that traditional sandboxing wasn't enough when running AI agent-generated code across thousands of life sciences tenants. Standard controls block HTTP, restrict egress ports, and limit outbound connections, but DNS resolution often stays permitted. Even when system defaults restrict it, teams may not have visibility into those restrictions. Benchling needed customer-controlled network isolation and continuous validation through its own integration test suite.
The architecture separates an Untrusted Code Account from the Production Account, with no internet gateway and no NAT gateway. DNS queries pass through a three-priority Route 53 Resolver DNS Firewall policy: P10 blocks known malicious domains, P100 allows only explicitly listed endpoints, and P200 returns NODATA for everything else. VPC endpoint policies restrict S3 access to specific buckets, and per-job credentials via AWS STS scope data access without one IAM role per tenant. Benchling first proved this in a proof-of-concept VPC, then added exfiltration simulations to its continuous integration test suite so any future infrastructure change that weakens the boundary fails the pipeline.
The stakes for Benchling hinge on whether those automated tests keep pace as VPC settings change, new endpoints are added, and IAM policies are updated. Regulated life sciences customers likely care most about the reported zero cross-tenant data leakage, since a single incident could undermine trust in AI-generated scientific workflows.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Meta introduced its Muse AI agent, triggering a rally in Intel and fellow chip stocks, while AMD reached a $1T…

Qualcomm announced that its Snapdragon X Series processors will power Googlebook, a new line of laptops descri…

Opro will hold a free online seminar on September 29 to October 1, 2026, introducing "Kamiresu," which digital…

Fujitsu said it will evolve Uvance, launched in October 2021, into an AI Transformation model, shifting to ind…

John Deere introduced JD, an AI assistant inside Operations Center that lets farmers ask questions about their…

OpenAI and Anthropic are close to signing a deal to stress-test each other's commercially released frontier AI…
