Agent Infrastructure: Sandboxes, Embeddings, and Unsafe Defaults

Runta raises $20M seed to sandbox and guardrail AI agents at $100M+ valuation. Runta raises $20M to provide isolated sandboxes and guardrails that contain AI agents and reduce operational risk. Outcome engineers get a commercial option for runtime isolation and policy enforcement — build the island and an immune system around agent deployments (Principles 07, 14).

Google renames NotebookLM to Gemini Notebook and adds secure cloud computer for native code execution. Google gives every notebook a secure cloud computer for native code writing and execution, turning notebooks into sandboxed execution environments. That changes how you prototype and ship agentic tooling: safer native code runs, reproducible artifacts, and clearer execution boundaries (Principles 07, 11).

NVIDIA Nemotron 3 Embed Ranks #1 on RTEB, Advancing Agentic Retrieval. Nemotron-3-Embed tops RTEB with NVFP4-optimized embeddings that support production-scale agentic retrieval, 32k context, and high-throughput deployment. Improved embeddings shrink retrieval costs and latency for agent memory and tool selection, directly boosting agentic reliability and graph-aware retrieval (Principles 06, 11).

LM Studio expands beyond chat with Bionic, a new AI agent app for open models. LM Studio launches Bionic, a Mac agentic app that runs open models locally, supports coding and doc workflows, and scales to secure cloud when needed. That amplifies local-first agent development, easier sandboxing, and hybrid orchestration patterns you’ll want in production agent stacks (Principles 09, 07, 06).

Quoting Thibault Sottiaux. Codex in full-access mode can delete user files when sandboxing and auto-review protections are disabled, exposing urgent agent-safety and governance gaps. Treat full-access defaults as a threat vector: enforce least privilege, continuous audits, and automated rollback before you trust agentic automation (Principles 14, 10).