
15 Sep 2026
NOFire open-sources Brig, a microVM sandbox for AI coding agents
Athens-based NOFire AI released Brig as an Apache 2.0 open-source project that runs AI coding agents inside a low-overhead microVM on Mac or Linux. The company says the tool is meant to contain package installs, network use, and credential access when developers give agents broad auto-approval — using CPU-enforced virtualization rather than process-only sandboxes.
Same-day company primary that a security boundary for everyday AI coding agents is shipping as open source — not another chat product. SAFETY desk signal that agent auto-approval is forcing the industry to push isolation down to hardware-backed microVMs.
NOFire AI, an Athens-based company, published “Brig is Open-Source: the microVM Sandbox for AI Coding Agents” on its company newsroom on 15 Sep 2026. The page is marked For immediate release, dated September 15, 2026, and datelined Athens, Greece. The company said it released Brig as an Apache 2.0 open-source project. Apache 2.0 is a permissive open-source license — you can use, change, and share the code, including in commercial products, if you keep the license notice. That company newsroom page is the filing event. These are company claims. This desk did not install Brig.
Purpose, as NOFire tells it: run AI coding agents inside a secure, low-overhead microVM on Mac (Apple Silicon) or Linux so infiltration and supply-chain-style attacks cannot freely own the host operating system when agents install packages, use the network, or touch developer credentials. A microVM is a tiny virtual machine that isolates an agent from the rest of your computer. The company names the “Axios supply chain attack” as the kind of infiltration it wants to contain. File that job and that example as NOFire’s. This desk did not replay that attack.
Mechanism, still company: hardware-level virtualization, with memory and process boundaries enforced by the CPU rather than a process-only sandbox. A process-only sandbox is software that tries to fence a program in without giving it its own virtual machine. The company says the microVM code a security-aware enterprise would have to audit is under 20,000 lines, and calls that one of the lowest-overhead sandbox technologies. File the hardware-enforced boundary, the under-20,000-line audit surface, and the “lowest overhead” line as NOFire’s. This desk did not count the lines or bench the overhead.
Availability, company: Brig is available today. Start with `brig run claude`. Curated profiles cover Claude Code, Codex, Cursor, Gemini, Grok, and opencode, or you can bring your own OCI images — a standard container image format — such as Ubuntu. The company says it runs on Mac with Apple Silicon and on Linux on Intel-compatible and ARM chips, including cloud hosts. The install script stays in Sources. File those names and the start command as NOFire’s. This desk did not run the installer.
Named voices on the company page: Anastasios Nanos, co-founder and chief scientist, on his urunc, unikernel, and microVMM background; and Moustafellos Panagiotis, co-founder and chief technology officer, on NOFire’s production Context and Control Model and controlled autonomy for remediation. urunc is a Cloud Native Computing Foundation sandbox project for unikernels and lightweight virtual machines. File the names and titles as the company’s. Their quotes are color only and stay in Sources.
Company context, still NOFire’s: the firm says it is building a Context and Control Model for Production — a live, time-versioned map of how production actually behaves, with governance on every agentic action. Brig is the open-source sandbox piece released today. File that map and that role as the company’s. This filing is not a production-ops product review.
Plain English for the rest of the card: microVM = tiny virtual machine that isolates an agent from the rest of your computer. Apache 2.0 = permissive open-source license. auto-approval = letting an AI coding agent run tools without clicking OK each time. OCI image = standard container image format.
PRIMARY here: NOFire AI’s 15 Sep 2026 company newsroom — Tier A company source, the original record. The project site at brig.sh is install and docs context, not a second originating newsroom. The Apache 2.0 release, the Mac / Linux microVM purpose, the hardware-enforced isolation claim, the under-20,000-line audit surface, the curated agent profiles, the Nanos and Panagiotis titles, and the Context and Control Model line are company-attributed. The company’s “lowest overhead” and 20,000-line claims stay company-attributed. NOT claimed: funding, a valuation, customer logos, CVE counts, an independent security audit, that this desk tested Brig, a stock tip, or investment advice. Distinct from the already-filed exein-270m-physical-ai.