5 quotes from 1 episode on The Changelog, each with a timestamped link to the source.
5 quotes1 episode
The short version
Developers act as architects who build strict environments for AI agents to operate securely. Gavriel Cohen explains that isolating each agent inside a Docker container and routing actions through a central gateway enforces data rules.
Most interesting insights
Building environments for AI agents consumes 50% of development time on a continuous basis.
“My perspective is we need to be spending a big portion of the time, maybe it's 50%, maybe it's even more, of setting up the right environment for the agent to be able to work effectively, and that's not a one-time set up. It's on a continuous basis.”
Gavriel Cohen, The Changelog · October 2026 · Listen ↗
Hardened containers isolate agents from one another
Multiple agents run on a single virtual machine. Every agent operates inside an individual Docker container sandbox, blocking access to data held by other agents.
“…one Nanoclaw deployment, one instance of Nanoclaw running in a VM, can run many different agents, and each of those agents are segregated in and isolated in their own sandbox, which is a hardened Docker container, and they don't have any access to information that other agents have access to.”
Gavriel Cohen, The Changelog · October 2026 · Listen ↗
An agent gateway intercepts all requests to inject credentials and enforce rules. These wiring pathways prevent an agent handling sensitive data from sending that information to an agent with internet access.
“Agents run in sandboxes. All requests are proxied through the agent gateway and are then, that's where policies are enforced and credentials are injected.”
Gavriel Cohen, The Changelog · October 2026 · Listen ↗
“With those wirings of which agent can talk to which agent and where there are these approval gates, you can enforce data access policies and control and prevent an agent that has access to really sensitive data from sharing that information with an agent that has access to the internet…”
Gavriel Cohen, The Changelog · October 2026 · Listen ↗
Asking an LLM to police its own boundaries fails; compliance rules belong in deterministic, non-AI code outside the model context window.
Gavriel Cohen built NanoClaw to isolate every agent inside a hardened Docker container sandbox on a single virtual machine within the customer's private cloud perimeter (AWS Bedrock, GCP Vertex, or Azure).
How we attribute quotes. Every quote was matched against the episode transcript, so the words and the timestamp are real (we trim filler words like "um", nothing else). The name comes from our written summary of the episode, and we use it only when a separate check of the captions finds that person on the episode. YouTube gives us no voice-by-voice transcript, so open the timestamp to hear who is talking. See a wrong name? Tell us and we fix or remove it.