Google open-sources gVisor
Alternative to full VMs for container sandboxing — the first user-space kernel that would seed an entire industry.
/ Where agents run code.
Compute sandboxes for AI agents — microVMs, containers, and snapshot architectures that let agents run code, browse the web, and persist state without crashing each other or the host.
◆46 vendors·Last update 2026-05-18
/ timeline · Industry chronology
From Google's gVisor open-source release to Rivet Agent OS — how AI-native compute went from a single milestone per year to one per week.
Total milestones
35
May 2018 → Jun 2026
Last 18 months
26
74% of all activity
Funding rounds
9
Seed → growth
Launches & GAs
12
Public products
Months from 1st AI sandbox
34
E2B seed → today
Milestones per year — the acceleration
Fig. 01 · annual count
Alternative to full VMs for container sandboxing — the first user-space kernel that would seed an entire industry.
MicroVMs with sub-second boot at scale — the substrate Lambda, Fly.io and a dozen sandboxes would later build on.
V8 isolates for edge functions with 1 ms boot — proves serverless can run inside a browser engine.
gVisor-based serverless compute aimed at data and ML workloads.
Full-stack development platform; early signal that container-platforms-as-a-service can fund up.
Edge-optimized container sandboxing; the security model that would become Sandbox SDK.
First dedicated "sandbox for AI agents" startup. Pre-ChatGPT-tooling-rush.
General availability for AI agent builders. The reference API the rest of the industry would copy.
Browser preview + isolated APIs; Cloudflare's edge primitives repositioned for agents.
"Built a beta on New Year's Eve without telling anyone." Dev-environment startup repositions overnight.
"Disposable computer" — copy-on-write checkpoints, fork-a-VM-in-25ms.
Kernel-native agent security. The category goes mainstream-developer-aware.
Tiered isolation model documented in public; reference design for edge sandboxes.
Valuation reaches $3.5B. Container security crosses into household-name territory.
Bain Capital leads; expands sandbox + BYOC infrastructure for enterprise.
Insight Partners; valuation north of $200M. The category-defining startup gets its A.
First Round leads; 25 ms resume becomes the new throughput benchmark.
$15.1M total raised before exit; first AI-focused consolidation in the space.
$700M valuation. Emergence Capital + GV. Browser-VMs cross the unicorn-adjacent line.
Meta-aggregator approach — abstract over every sandbox provider.
Local-first microVMs distributed as .smolmachine files. New artifact format.
Unified virtual filesystem for sandboxed agents — read-anywhere, write-isolated.
AI sandbox tuned for dev-workflow snapshots; positions against E2B for code-execution.
Container-free OS-level sandboxing — sidesteps the runc/OCI surface entirely.
$3.5B valuation re-stated as round closes; security tooling continues to scale.
Sub-100 ms boot via Firecracker. The largest frontend platform ships sandbox-as-primitive.
FirstMark Capital leads. The Jan-2025 NYE pivot pays off thirteen months later.
Multi-provider Python library — write once, run on any sandbox backend.
Semantic-grep filesystem; agents search code by meaning, not regex.
CNCF-listed; multi-engine. Open-source momentum from Asia hits hockey-stick.
"Vercel for AI agents." Bundles compute, sandbox, and agent runtime into one deploy target.
Custom bare-metal hypervisor; targets long-running agent sessions where snapshots matter.
14 ms container boot. Edge sandboxing reaches CDN-grade global coverage.
Local-first sandbox with built-in MCP server — agents bring their own tools.
V8-based; 6 ms cold start. New floor on what "instant compute" means.
● funding · ● launch · ○ release · ◇ milestone — 9 rounds, 12 launches, 35 total