AI Briefing
KOSign in

Microsoft releases Quicksand, an async Python API for sandboxing AI agents with QEMU

·2026.10.09 09:00

Key point

Quicksand provides pre-built Linux VMs for Ubuntu and Alpine that run without root privileges or Docker.

Details

Microsoft has released Quicksand, an async Python API designed to launch, control, and snapshot QEMU virtual machines specifically for sandboxing AI agents. The tool provides pre-built Linux VMs for Ubuntu and Alpine distros, supporting x86_64 and ARM64 architectures across macOS, Linux, and Windows. Running sandboxes requires no root privileges or Docker, with bundled runtime options available for supported platforms.

Core Capabilities

Quicksand allows developers to execute commands, mount host directories, and configure networking within isolated VM environments. Key features include:

  • Network Isolation: Sandboxes are network-isolated by default, with optional full internet access and port forwarding via NetworkMode.FULL.
  • State Management: Users can save VM disk states to directories for later loading on different machines, or use checkpoint and revert functions to roll back changes.
  • Multi-User Support: Multiple agents can operate with independent Linux user accounts within a single sandbox VM.
  • Desktop Control: Desktop images provide a full Xfce4 graphical environment, enabling screenshot capture, keyboard input, and mouse control.

Available Images

The platform offers several pre-built images, including headless bases and desktop overlays. Sizes are approximate for the September 14, 2026 releases:

| Image | Type | Wheel Size | Description | | :--- | :--- | :--- | :--- | | ubuntu | Base | ~309-357 MB | Ubuntu 24.04 headless | | alpine | Base | ~82-85 MB | Alpine 3.23 headless | | ubuntu-desktop | Overlay | ~273-281 MB | Ubuntu 24.04 + Xfce4 + Firefox | | alpine-desktop | Overlay | ~346-363 MB | Alpine 3.23 + Xfce4 + Chromium | | quicksand-agent | Overlay | ~306-335 MB | Ubuntu + Python 3.12, uv, build-essential | | quicksand-cua | Overlay | ~489-500 MB | Agent Sandbox + Xvfb, x11vnc, noVNC, Playwright |

Installation and Configuration

Quicksand is installed via pip, with optional extras for QEMU and specific images:

pip install 'quick-sandbox[qemu,alpine]'

Configuration options allow customization of memory, CPU cores, disk size, and network modes. The API supports both static mounts at boot and dynamic mounting on running sandboxes.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.