Dev News Daily ENDE

Agents become infrastructure: permissions, runtimes and training data

Three announcements this week treat AI agents less as a model feature and more as something operations teams have to run, permit and maintain. Each answers a different practical question.

What may the agent touch? Docker's answer is an image. The Sandbox Kit Specification, version 3, which Docker is taking to the CNCF, packages an agent, its tools and a typed list of the hosts, credentials and volumes it requests into an ordinary OCI image. Deny rules win, real tokens can stay outside the sandbox behind a proxy, and a runtime can block an update that widens the grants. The caveat Docker's own coverage admits: a Kit only requests, enforcement is the runtime's, and only one runtime conforms so far. Source: https://www.infoq.com/news/2026/10/docker-sandbox-ai-agent/

Agents become infrastructure: permissions, runtimes and training data
Agents become infrastructure: permissions, runtimes and training data — Dev News Daily

Where does it run, and who pays while it waits? DigitalOcean's answer is a managed session. Managed Agents, in public preview, runs agents in microVM sessions that keep state, pause when idle and can be forked, and routes tool access through one gateway with central permissions, human approval for sensitive actions and rate limits. Source: https://www.infoq.com/news/2026/10/digitalocean-managed-agents/

How does it get better at this particular company's work? ServiceNow's answer is targeted training data. AutoSynthData finds the tasks an agent fails, has a teacher model demonstrate them, generates new tasks around the same capability and rejects any task whose verifier would pass a wrong outcome. In its EnterpriseOps Gym tests, mean Pass@1 rose 7.2 points in one domain and from 18.77% to 27.18% in another. Source: https://huggingface.co/blog/ServiceNow-AI/autosynthdata

What connects them. All three move something that used to be informal into an artifact that can be reviewed: permissions into an image layer, agent state into a managed session, and an agent's weaknesses into a validated dataset. That is how software usually becomes operable. The gap is the same in each case, too: the artifact is only as good as what enforces or checks it, whether that is a conforming runtime, a gateway's approval rule or a verifier that can actually fail. Teams adopting any of these should ask first who enforces the declaration, and test that it says no.

Written by Victoria Shinder.