Firecracker is a microVM (a stripped-down VM) AWS built in-house in 2017 for Lambda serverless functions—about 125ms cold start, capable of running thousands of isolated instances per host. A decade later, the AI Agent industry has collectively picked it back up as a code-execution sandbox, because container-style isolation (Docker and similar schemes that share the host kernel) is now considered insufficient. We care about this because when AI Agents enter the enterprise, "can the code run safely" is the first gate of compliance.

What this is

When an Agent needs to execute user-submitted code (e.g., asking the AI to run a Python script for accounting), it needs an isolated environment to prevent privilege escalation or malicious behavior. Docker-style containers share the host kernel, giving them a large attack surface. microVMs have an independent kernel and resource quotas—isolation strength close to a traditional VM, startup speed close to a container. There's a new technical wrinkle: container images (the OCI standard format) can't be used directly as a VM disk. You need to merge the layered filesystem, handle "whiteout" markers, and bolt on kernel modules plus an init boot script.

Industry view

The mainstream is following. Anthropic recommended the "code execution + MCP" pattern running inside a sandbox in a tech blog post last year; E2B, Daytona, and other Agent sandbox providers all run Firecracker underneath. What investors see: any enterprise building "Agents that can run code" can't bypass sandbox infrastructure—it's table-stakes engineering.

There's dissent too. The container camp argues that microVM cold start adds tens of milliseconds, operations requires knowing KVM (the Linux kernel virtualization module) and kernel trimming, and self-hosting costs are high. High-frequency code completion products find container + gVisor (a user-space kernel sandbox) more cost-effective. Whether OpenAI and Anthropic run all of their internal Agents on Firecracker is also not publicly stated—we can't assume "every Agent runs on it."

Impact on regular people

For enterprise IT: if your company wants to deploy AI Agents that execute code (financial automation, data analysis), security audits will check the isolation level—containers may fail compliance review, and microVM is the safer default.

For individual knowledge workers: when AI coding tools like Cursor, Devin, or Tongyi Lingma occasionally "pause for a moment before producing results," it could be microVM cold-start cost in the background—not necessarily a bug.

For the consumer market: billing for Agent sandboxes by execution duration is becoming a new business model, much like AWS Lambda did back then—users don't see the VM, but the bill will show it.