Enterprise Security Teams Clear Docker YOLO Mode; Find `--dangerously-skip-permissions` Honest Enough
SAN FRANCISCO—Docker's release of YOLO mode, an execution environment for autonomous AI coding agents that bypasses human oversight via a flag its documentation names --dangerously-skip-permissions, received security approval at 19 enterprise organizations this week following a legal review that found the flag name constituted adequate informed consent under EU AI Act transparency provisions, NIST AI Risk Management Framework Tier 2 standards, and the internal disclosure policy of a major US bank whose guidelines require only that products "clearly communicate intended behavior."
The product, Docker Sandboxes, runs AI coding agents in isolated microVMs without user supervision and supports models from Anthropic, Google, Microsoft, and OpenAI. Installation requires a single terminal command. Docker's documentation describes YOLO mode as suited for scenarios where agent performance is degraded by human involvement in the loop, a framing the company has positioned as a use-case description rather than a known risk.
Enterprise security teams reviewing the product noted that in four years of AI tool approvals, YOLO mode was the first they had encountered whose name matched its function. Previous approvals this year had included tools marketed as Harmony, TrustBridge, and SafeLayer, and a platform sold as "Responsible by Design" that had been involved in two separate incidents.
"The word 'dangerously' is not nothing," said one compliance officer, speaking on background. "We have been approving AI products for four years and none of them said that."
Docker's telemetry tracks whether YOLO mode agents complete their assigned tasks. The metric does not capture what tasks were assigned, by whom, or at what scope. Eighteen of the 19 approving organizations confirmed agents had already been deployed.
The nineteenth was still reading the documentation.