Cloud Run sandboxes entered public preview on July 10. You run code written by an AI agent, and it doesn't touch the rest of your system. What matters is in the default: zero outbound network access, zero visibility into the service's keys.
- Cloud Run sandboxes entered public preview on July 10, 2026, announced at the WeAreDevelopers World Congress.
- By default: zero outbound network access and no visibility into the service's environment variables and metadata.
- They start in milliseconds on the service's already-allocated CPU and memory, at no extra charge.
Google announced Cloud Run (Google's hosting service) sandboxes - a room where you run code written by an AI agent, without it reaching the rest of your system. The announcement's headline says it plainly: how to safely run code generated by AI.
Here's the value - in the order things are arranged. Closed by default and opened deliberately, not the other way around. Until now, everyone drew this boundary themselves, with manual rules and attention to how far the keys reach. Now a big cloud provider hands it over ready-made, without charging for it. The admission inside the product is more interesting than the feature itself: code an agent writes is treated as untrusted code.
The landing is practical. If agents write code for you - for analysis, for a headless browser, for third-party plugins - this is the protection you'd otherwise have to build yourself. Just don't take it on faith. Preview isn't production. Check exactly what's allowed in your configuration, and try to exfiltrate a file from the sandbox yourself before you believe it can't be done.