By: Nithya Rao, System and Software Optimization Engineer, Intel Corporation
Contributors
Jun I Jin, Principal Engineer - Cloud and System Performance, Intel
Michael Zhang, Cloud Software Architect, Intel
Rohan Vaidya, Software Engineer, HCL Technologies
Agentic AI systems are evolving beyond simple question and answer interactions. Modern AI agents can execute code, process files, query databases, interact with application programming interfaces (APIs) and perform multi-step workflows on behalf of users. While these capabilities unlock new levels of automation, they also introduce new infrastructure and security requirements. Executing agent-generated code directly on a host system can expose organizations to software bugs, prompt-injection attacks, data leakage, or privilege-escalation risks.
To address these challenges, agentic AI frameworks rely on isolated execution environments, commonly referred to as sandboxes. As AI agent adoption grows, sandboxing becomes more than a security feature. Agents frequently create, use, and destroy execution environments within seconds, making sandbox provisioning efficiency a key component of overall responsiveness and scalability. The ability to combine strong isolation with rapid provisioning is becoming increasingly important for large-scale agentic AI deployments.
Sandboxing: A Core Component of Agentic AI
Several sandboxing approaches are commonly used today, including virtual machines, containers, microVMs, and the open-source Tencent Cloud Cube Sandbox. While these technologies provide stronger security and isolation, they also require infrastructure to efficiently provision and manage isolated execution environments at scale.
The Sandbox Lifecycle
In a typical agentic AI deployment, sandbox creation sits directly on the critical path of task execution. Before an agent can run code or invoke tools, a sandbox must first be provisioned, initialized, and made available for use.
A simplified execution flow is shown below:
Agent request → Sandbox creation → Task execution → Result return → Sandbox teardown
In large-scale agent deployments, sandbox creation and teardown occur continuously as workflows execute. The efficiency of this lifecycle can have a direct impact on application responsiveness, infrastructure utilization, and overall throughput.
Evaluating Sandbox Provisioning Performance
To evaluate sandbox provisioning performance under realistic operating conditions, Intel used the cube-bench create/delete workload, which measures how efficiently a platform can provide new sandbox environments.
The workload continuously issues sandbox creation requests through the CubeSandbox API while increasing aggregate concurrency. This approach assesses how effectively a platform can sustain provisioning demand as the number of concurrent sandbox requests grows.
A key metric in this evaluation is the 200-millisecond sandbox creation service-level agreement (SLA), which represents the target responsiveness threshold for delivering a usable sandbox environment. Average create-latency, along with throughput and tail-latency metrics, provides insight into how effectively a platform maintains responsiveness under increasing load.
Intel Xeon Processors Delivers Greater Provisioning Scalability than AMD EPYC Processors
Figure 1 below shows average sandbox creation latency as concurrency increases from 100 to 350 concurrent provisioning requests. While all platforms exhibit increasing latency under heavier load, platforms based on Intel® Xeon® processors maintain lower creation latency and sustain higher provisioning concurrency within the target 200-millisecond service-level objective. The Intel® Xeon® 6990E+ processor remains below the 200-millisecond SLA until approximately 313 concurrent provisioning requests. The Intel® Xeon® 6980P processor remains below the same threshold until 277 concurrent requests. In comparison, the AMD EPYC™ 9965 processor crosses the 200-millisecond threshold at approximately 246 concurrent requests. Compared with the AMD EPYC 9965, Intel Xeon 6990E+ processor supports roughly 27% higher provisioning concurrency within the 200-millisecond SLA, while Intel Xeon 6980P processor supports approximately 12% higher concurrency.
As provisioning demand increases, both Intel processor-based platforms continue to deliver strong scalability and predictable latency behavior. The platform based on the Intel Xeon 6990E+ processor provides the highest concurrency within the 200-millisecond target. The platform based on the Intel Xeon 6980P processor also maintains the SLA at substantially higher provisioning levels than AMD EPYC 9965 processor. These results demonstrate the ability of Intel Xeon platforms to sustain higher sandbox provisioning rates while maintaining responsive and consistent service-level performance underload.
Figure 1. Intel Xeon 6990E+ processor maintains consistently lower average create latency across an aggregate concurrency increases from 100 to 350.
Final Takeaway
As agentic AI systems become more capable, sandboxed execution is becoming a foundational requirement for secure deployment. At the same time, organizations must balance isolation with responsiveness. Because sandbox creation is directly in the critical path of agent execution, provisioning performance can significantly affect the user experience and overall infrastructure scalability.
These results demonstrate that Intel Xeon 6 and Xeon 6+ processors provide a strong foundation for large-scale sandboxed agent deployments, combining the scalability needed to support growing numbers of concurrent agent workflows with the responsiveness required for modern, action-oriented AI systems. As agentic AI workloads scale, the ability to efficiently orchestrate, isolate and provision large numbers of agents becomes increasingly important. Intel Xeon 6 and Xeon 6+ processors are designed for these demands, enabling higher agent density and faster provisioning than the alternative platforms tested.
Product and Performance Information
Configuration Details: Results may vary.
Tencent CubeSandbox:
Intel Xeon6+: One-node, Supermicro SYS-212HA-TN system, One Intel Xeon 6990E+ processor, 288 cores, 450-watt thermal design power; hyperthreading no applicable, Intel Turbo Boost Technology on, 768GB total memory using 12 64GB DDR5-6400 modules operating at 6,400 megatransfers per second, BIOS version 1.5b, microcode 0x1000120, two Ethernet Controller X550, two Ethernet Controller E835-CC for QSFP,1x 1.7T KIOXIA KCMYXRUG1T92, one 1.7T SAMSUNG MZ1L21T9HCLS-00A07 drive, CentOS Stream 9, version 7.1.0. Tested by Intel as of September 2026.
Intel Xeon 6: One-node, Intel Corporation Avenue City system; one Intel ® Xeon ® 6980P processor; 128 cores, 500-watt thermal design power; hyper-threading technology enabled, Intel Turbo Boost Technology enabled; Total Memory 768GB total memory, using 12 64GB DDR5-8800 modules operating at 8,800 megatransfers per second, BIOS BHSDCRB1.IPC.3545.P40.2603170757, microcode 0x1000430, one I210 Gigabit Network Connection, two Ethernet Controller 10-Gigabit X540-AT2 devices, two 1.7T KIOXIA KCD8XPUG1T92 drives, one 894.3G Samsung MZ1L2960HCJR-00A07 drive, CentOS Stream 9, version7.1.0. Tested by Intel as of September 2026.
AMD: One-node, Supermicro AS-2126HS-TN system; one AMD EPYC 9965 192-core processor; 192 cores; simultaneous multithreading enabled; boost enabled; 768GB total memory, using 12 64GB DDR5-6400 modules operating at 6,400 megatransfers per second; BIOS version 1.9; microcode 0xb101059; two Ethernet Controller E810-C devices for QSFP; one AX88179 Gigabit Ethernet device; one 1.7T KIOXIA KCD8XPUG1T92 drive; one 1.7TB Samsung MZ1L21T9HCLS-00A07 drive; CentOS Stream 9, version 7.1.0. Tested by Intel as of September 2026.
Test Methodology:
Benchmark: CubeSandbox create/delete workload against template common across platforms, instance_type cubebox, template version v2, (OCI - Open Container Initiative) source image cube-sandbox-cn.tencentcloudcr.com/cube-sandbox/sandbox-code@sha256:743d264fad8c9dc9a49f07e931166d24d025363360ae770ca4b70e3f19540944.
Load: Each sandbox was provisioned with 2,000 milliCPU, equivalent to two CPUs, and 2000mebibytes of memory, or approximately 2 gibibytes. The test used in-path egress in-path with mutual Transport Layer Security and the cube-egress certificate authority included in the image. Aggregate concurrency increased from 100to 350 concurrent sandbox creation requests.
Metric: The test measured average sandboxcreation latency, in milliseconds, as concurrency increased; crossing point marks where average latency exceeds the 200–milliseconds reference threshold.
Notices and Disclaimers
Performance varies by use, configuration, and other factors. Learn more on the Performance Index site.
Performance results are based on testing as of the dates shown in configurations and may not reflect all publicly available updates. See backup for configuration details. No product or component can be absolutely secure.
Your costs and results may vary.
Intel technologies may require enabled hardware, software, or service activation.