The fourth-generation Blaxel runtime adds microVM isolation, dedicated IPv6 addresses, snapshots and forks; access is rolling out in a private preview.
By [Ryan Merket](https://runtimewire.com/author/ryan-merket)
· Published
Primary source: [X](https://x.com/baseten/status/2104995956441682313)
Why it matters #
Baseten is extending its inference platform into the infrastructure where agents execute code and use tools. Carbon's private preview shows how its Blaxel acquisition may become a product, while leaving adoption, production performance and commercial terms to be proven.
Baseten put Carbon, a new agent-execution platform built on the Blaxel sandbox infrastructure it acquired, into private preview on September 28th. The release adds support for NVIDIA's OpenShell runtime, which enforces policies around an agent's actions. Baseten CEO and co-founder Tuhin Srivastava (@tuhinone) is pitching a product that extends the company's model-serving business into the environment where AI agents run code and use tools. Baseten linked its announcement from a September 29th post on X.
Carbon is Blaxel's fourth-generation infrastructure. Baseten says each sandbox runs in a microVM and receives a dedicated IPv6 address. The preview supports kernel capabilities and runtime enforcement, along with manual snapshots and forks. A sandbox can be started from a snapshot and moved toward production within milliseconds, according to the company's announcement. Carbon is in private preview, rolling out by region and workspace.
The OpenShell integration connects an agent's security monitor to controls over what it can do. NVIDIA describes OpenShell as an open-source runtime that enforces policy outside an agent's own process. Baseten says developers can boot a Carbon sandbox from a template with OpenShell installed. If OpenShell flags and quarantines an agent during a task, Carbon's snapshot feature is designed to restore the environment to a prior state rather than discard the whole run.
That setup addresses a practical gap in agent deployment: a model may generate an action, but the surrounding system still has to decide what code it can execute, what data it can reach and how to recover from a bad step. Sandboxing can isolate execution; policy enforcement can restrict access; snapshots can preserve a recovery point. Carbon's pitch is to put these controls in the execution layer alongside the tools and persistent state an agent needs. The product's private-preview status means the announcement describes a developing offering, not yet a broadly available service.
For Srivastava, the move follows the same infrastructure problem that shaped Baseten at its founding. He and his co-founders met while working together at Gumroad, where Srivastava and co-founder Phil Howes trained a fraud classifier. In an interview with Software Engineering Daily, CTO and co-founder Amir Haghighat said model training was straightforward; operating the model quickly and reliably in production was the harder task. Srivastava had previously co-founded Shape, later acquired by Reflektive, and worked as a data scientist at Gumroad. Baseten started in 2019 around the production bottleneck; Carbon takes that infrastructure ambition from model serving into agent execution. Baseten's September 10th acquisition announcement said Blaxel brought isolated sandboxes, persistent storage and networking for agents, while Baseten supplied model training and inference. The companies said they would combine those layers, with Baseten planning to build products around Blaxel's underlying technology, starting with sandboxes. Carbon is an early concrete step in that integration. The acquisition's financial terms were not included in either company's announcement.
The timing also puts the product beside NVIDIA's newly announced Open Agent Safety Platform. NVIDIA said on September 28th that OpenShell is part of that platform, which is intended to provide security controls for agents from testing through deployment. Baseten says it is a launch partner for NVIDIA's effort and part of the Open Secure AI Alliance. The company's announcement of the partnership and Carbon preview makes the connection explicit: runtime monitoring matters more when it can trigger restrictions, isolation or rollback in the system where the agent acts.
Baseten has been financing a broader expansion beyond inference. On June 22nd, it announced a $1.5 billion Series F at a $13 billion valuation, led by Altimeter Capital, Conviction Partners and Spark Capital, with Sands Capital and Wellington Management co-leading. Baseten reported 20x year-over-year revenue growth and 40x growth in inference volume in that announcement; the figures were company-reported. Carbon adds a new product surface to that push, but the preview leaves the commercial test ahead: whether customers will adopt a combined model-serving and agent-execution stack, and whether the new runtime's security and recovery controls hold up under production use.