The AAIF now has a Sandbox phase. The old entry bar was the wrong test for a layer this young.
Over the past few months I have had roughly the same conversation a dozen times. A maintainer has built something the agentic ecosystem plainly needs. The code works. The license is clean. And they do not come close to qualifying for the Agentic AI Foundation, because our entry bar asked for wide-scale production use and maintainer diversity - a bar the newest work has no way to clear yet.
Recently, the Governing Board and Technical Committee approved a fix: a Sandbox phase, below Growth, for projects that are technically real, with momentum, but otherwise early.
Lifecycle that matches the pace of AI
The AAIF started with two phases for active projects: Growth and Impact. Growth required a project be "used successfully in production at a wide scale." Impact required "wide-scale impact and substantial production deployments." Those are nearly the same sentence, and I think I know where they came from.
Everyone reaches for CNCF as the model, us included. But look at what CNCF was actually founded on. Kubernetes, with a decade of Borg behind it and the entire industry already adopting it. Then Prometheus, mature and running in production. That was 2015 - cloud computing was nearly ten years old and the shape of the problem was settled. A high entry bar was the right call, because there was a supply of projects that already cleared it.
Agentic AI is roughly two years old. We inherited CNCF's bar without inheriting CNCF's conditions or environment.
MCP, A2A and Goose cleared that bar comfortably, which is why this took a while to surface. But a foundation whose only door is that one, only ever admits work that has already won.
Consider what keeps arriving instead:
- Infrastructure for context management and compression, with a production user or two but with incredible community momentum - real, but nowhere near wide scale, because the deployment patterns are still being worked out.
- A developer tool with viral traction, respected benchmarks, broad framework integrations, and one maintainer.
- Distributed inference infrastructure with Growth-grade engineering velocity but hobbyist adoption, because nobody has settled how you deploy this yet.
- A durable agent framework sitting at the intersection of emerging standards of workflows and process automation, but with commit dominance by the company that started it.
Every one is technically mature, with community momentum, but immature by the metrics asked for by Growth. Every one is at the exact moment when governance is cheap to install and expensive to retrofit. And under the old policy the only options were to turn them away or stretch Growth until the word meant nothing.
What Sandbox actually is
Three phases, judged on the same three axes, with the bar rising consistently across them: adoption, community, and foundation commitment.
Sandbox entry is a working implementation plus either early external interest or a credible thesis - a protocol that needs to exist counts. A named, active maintainer. And in return: standard infrastructure only. No funding, no marketing, no scanning. A home and a neutral flag, nothing more.
Graduating to Growth needs all three: production use by two unaffiliated organisations, commits from two or more organisations over six months, and a written growth plan accepted by a TC sponsor - including the project's own definition of what Impact would look like for it.
We also tightened Growth itself. "Wide-scale" now belongs to Impact, where it always meant something.
The exit clock, and why it matters
Sandbox comes with a six-month checkpoint and a twelve-month window to apply for Growth. Miss it and the TC opens an archival discussion.
This is the part I would push back on hardest if I were reading someone else's proposal, so let me be direct about it. A foundation that lowers its entry bar can reasonably be accused of collecting projects. The exit clock is the answer: Sandbox is built to let projects leave, on their own terms. Archival is not failure. It is the model working.
We will publish three counters at every annual review - acceptances, graduations, archivals. If the archival counter is still zero in two years, we are being too conservative, and you should hold us to that. A phase where nothing ever exits is a phase that has quietly become a trap.
That is the whole bet. Neutral governance installed before a project accretes is supportive. Retrofitted later, it is adversarial - CNCF paid that bill with OpenTracing and OpenCensus, and the merger pain was governance pain, not technical pain. Sandbox exists so we stop sending that invoice.
If you maintain something
Apply. If you have a working implementation and a thesis for why your layer needs to exist, you are in scope - and if you are single-maintainer with sudden traction, you are in the highest-risk position in open source, whether or not it feels that way right now. A neutral home gives you something to recruit co-maintainers into.
If your company is building on agentic infrastructure: this is where the projects you will depend on in three years are sitting today, unfunded and ungoverned. Participation is cheaper now than a fork later.
The policy is here. Pressure-test it publicly. Some of it - the two-organisation bar, the aggressiveness of a 12 month clock against CNCF norms - is a judgement call we made rather than a truth we discovered, and we would rather argue about it in the open than discover we were wrong in year three.
Foundations that catch projects early keep them. Foundations that wait, do not.
Share
Author

Manik Surtani
View All PostsManik Surtani is CTO and co-founder of the Agentic AI Foundation, where he is responsible for the foundation’s technical output — the reference architecture, standards and protocols, and the work of its technical working groups — and partners with the Technical Committee and project maintainers to shape which projects join the foundation. Prior to AAIF, Surtani was Head of Open Source and VP of Cloud Infrastructure at Block, and earlier a Staff Engineer at Red Hat. He is the creator of Infinispan, the distributed in-memory data grid, and represented Block in the collaboration with Google that produced gRPC. He is also a public speaker, investor, startup mentor – and outside of work, a rock climber, mountaineer, and wannabe surfer.



