Brain: a WebAssembly agent runtime betting on isolation as the answer to agentic AI's security failures

🕒 Published on Zendoric: September 3, 2026 · 10:20
✨ AI-generated · how it's made
Aexhq has released Brain, an open-source agent runtime that runs each decision loop in a WebAssembly sandbox and records every step in a reproducible log. It's a tiny, early-stage project, but its design points to a real concern: how to contain autonomous agents without slowing them down.
By Zendoric · September 2, 2026.
Aexhq has published Brain on GitHub, an open-source agent "runtime": the server that runs an AI agent's session, manages its model calls and coordinates the tools it uses (looking up an order, running code, browsing a website). According to the project's own documentation, each idle session takes up about 14 KiB of memory and a full round-trip turn takes 40 milliseconds, figures that aexhq itself compares with seven other similar runtimes — ZeroClaw, OpenFang, AgentScope, Letta, LangGraph, Awaken and OpenClaw — in a benchmark published in its repository (BENCHMARKS.md) which, it is worth stressing, is an exercise by the company itself, not an independent measurement.
The most interesting technical piece is not the speed, but the architecture. The "agent loop" — the logic that decides what the agent does at each step — is compiled to WebAssembly and runs in a Wasmtime sandbox with no access to the file system, network, clock or credentials of its own: it is Brain that carries out any effect on its behalf. Every decision, model call and tool result is recorded as an event in an append-only log ("write-ahead log"), which makes it possible to reproduce exactly what an agent did and why. The project is in "early preview": aexhq itself warns that the API may change without backward compatibility before a 1.0 release.
It is worth calibrating the real size of this: it is a repository with 11 stars on GitHub and a Hacker News post that drew barely one vote and two comments. There is no funding announcement, no known customer and no documented traction. It is, strictly speaking, a very early-stage developer tool, not a market event.
Its interest lies not in the project itself, but in what it confirms as a pattern. In recent weeks we have seen how the autonomous agent economy is beginning to need its own "plumbing": payment standards that let an agent charge without human approval, chipmakers redirecting their roadmaps toward agent orchestration. Brain fits into that same category: low-level infrastructure that does not compete to be the smartest model, but to be the layer that executes, isolates and audits the agents using that model. The more runtimes of this kind appear — and aexhq's own benchmark already lists seven direct competitors — the clearer it becomes that the fight over agentic AI is also being waged, and perhaps above all, over who controls that execution layer.
The emphasis on sandbox isolation and on a reproducible record of every decision is no accident either. As sector context, the concern that an agent may act outside its intended limits is pushing the answer down two paths: restricting access to the most dangerous capabilities, or containing by design what an agent can do and leaving a trace of every step it takes. Brain bets on the second path. It is a reasonable answer to the underlying problem — increasingly autonomous agents that need technical governance, not just promises — even if in this case it comes from a project so young that it has yet to show whether it will survive the glut of frameworks competing for the same slot.
Our read is that announcements of this kind, individually minor, are the best gauge of where AI infrastructure is heading while media attention is fixed on the large models. The abundance we defend in the long run depends not only on models becoming more capable, but on the existence of a cheap, auditable and traceable execution layer in which millions of agents can operate without every failure turning into a security incident. Projects like Brain, even if today they are an experiment with 11 stars, are the kind of plumbing that, if it succeeds, no one will notice because it will simply work.
🔗 Related on Zendoric


