Definition
Operating-system technology that runs an AI agent inside a restrictive container whose limits are set by external security policy rather than by anything the agent itself can change. The agent cannot grant itself new access because the policy sits outside its control. This is the OS-level answer to rogue or over-privileged AI agents.
Why it matters
Containment limits the blast radius when an agent is tricked or misbehaves, making a single compromised agent far less likely to become a full system compromise.