Abnormal AI, a behavioral security service, has deployed Amazon Bedrock AgentCore Code Interpreter to enhance its real-time inline email threat detection. These systems process billions of messages daily, executing agent-driven code at the same scale to detect and block threats before they reach inboxes.

The Code Interpreter provides a fully managed, serverless runtime for agents to execute code dynamically, with features like ephemeral MicroVM sessions, secure sandboxes, and flexible networking. It is exposed as an API, allowing agents to run commands, upload files, and retrieve results without dictating workflow.

Abnormal AI uses a three-tiered detection architecture, with Tier 3 employing inline agents with Code Interpreter to handle the hardest cases. These agents receive threat intelligence data, analyze it in a sandbox, and make determinations on how it fits into the overall behavioral model.

"Pretty much any agent, whether it’s writing code or not, needs a code interpreter sandbox that allows it to actually crunch data and come to answers," said Shrivu Shankar, VP of AI Strategy, Abnormal AI. The sandbox design ensures reproducibility and data exfiltration prevention by isolating agents from external network access.

The announcement follows Abnormal AI’s ongoing efforts to integrate AI-native approaches into its production runtime. The company did not specify the exact number of messages processed daily, and it remains unclear how the system handles misclassifications in real-time.

Source: awsml