BlogsDocker Feature Trails

Docker logo

Docker Feature Trails

See how major capabilities shipped, upgraded, and evolved across Docker's engineering blog.

Feature trails

3

AI Agent Isolation and Secure Execution

Active

This feature thread tracks Docker's advancements in providing secure and isolated execution environments for AI agents. Initially, the focus was on the growing need for isolation as AI agents shifted from passive assistance to active code execution. Subsequent posts detail Docker's solutions, including Docker SBX (Sandboxes) which leverages microVMs for enhanced security, and Sandbox Kits for creating reusable, standardized, and secure AI development environments. This post highlights the importance of governance as a developer experience problem, emphasizing that clear boundaries and platform-embedded controls build trust, which is crucial for scaling AI agent adoption. It argues that governance, when integrated into the platform, reduces uncertainty for developers, enabling them to delegate work and focus on outcomes, thereby improving developer experience and facilitating wider adoption of AI agents.

9 posts

Timeline

Developer Productivity and Security Tooling

Active

This feature thread tracks Docker's evolution in providing tools and guidance to enhance developer productivity and security. Initially, the focus was on core containerization capabilities and community engagement. Subsequent posts detail advancements in areas like secure execution environments (e.g., Docker SBX, Sandbox Kits), improved build processes (e.g., Docker Bake, SBOM generation), and the integration of security best practices directly into the development workflow. This post highlights the increasing importance of software supply chain security, driven by the rise of AI and third-party code usage, and emphasizes the role of developers as the first line of defense. It discusses findings from Omdia's 2026 report, including the prevalence of supply chain incidents, the top risks associated with AI and third-party code, and the effectiveness of secure containers and SBOMs in mitigating these risks. The post also touches on investment plans and the priority of 'shifting security left' to empower developers.

4 posts

Timeline

EU AI Act Compliance

Active

This post details the specific requirements of the EU AI Act across its four risk tiers (unacceptable, high, limited, minimal). It outlines the compliance timeline, including phased enforcement and the Digital Omnibus adjustments, and elaborates on the obligations for providers and deployers of high-risk AI systems. Key requirements for providers include establishing risk management systems, ensuring data governance, maintaining technical documentation, implementing record-keeping and human oversight, achieving accuracy, robustness, and cybersecurity, establishing quality management systems, taking corrective actions, cooperating with authorities, appointing authorized representatives, completing conformity assessments, and conducting post-market monitoring and incident reporting. For deployers, obligations focus on using AI systems under their authority and interpreting system outputs appropriately. The post also highlights transparency obligations for limited-risk systems, such as marking synthetic content and disclosing AI interaction.

1 post

Timeline