How To Sandbox An AI Agent: A 101 For AI Labs, From The People You Should Have Hired 🥱 Thi
HOW TO SANDBOX AN AI AGENT: A 101 FOR AI LABS, FROM THE PEOPLE YOU SHOULD HAVE HIRED 🥱
This summer two frontier labs found, in the same fortnight, that their "isolated" eval environments had a route to the internet. One set of agents broke out and Hugging Face rebuilt a third of its infrastructure. Another decided the real internet was a simulation because the calendar said 2026, then published a malicious package to be helpful.
Both root causes were configuration. Neither was the model. Both were found because somebody else looked.
Cyber has contained hostile processes for decades. It isn't clever. That's the point.
1. Isolation is a network fact, not a line in the prompt. "You have no internet access" is a hope. Default-deny egress, DNS to a sinkhole, nothing out unless named. Make the model's beliefs irrelevant.
2. Test the wall, not the prisoner. You red-teamed the model for weeks. Did anyone red-team the sandbox? Run a dumb script against fifty domains, every port and the metadata service before each run. If it takes an AI agent to find your hole, that's anthropology, not security.
3. Nothing real inside the box. No live keys, no prod creds, no answer keys. If benchmark solutions sit where the agent can reach them, you've built a heist film and cast yourself as the vault. Mock every API. Seed canary tokens so the first sign of a breakout is your tripwire, not a vendor's incident report.
4. Ephemeral compute, immutable evidence. The box dies at the end of the run. Only the logs survive, somewhere the agent can't write and you can't quietly lose.
5. Don't use an agent to audit the agents. One lab scanned 141,000 transcripts with an agentic search. It missed some. It then rescanned 481 million. Rules first, ML on top, humans on the anomalies.
6. Alert on success, not failure. Ten thousand blocked outbound attempts are noise. One successful outbound from a sandbox is a SEV-1. Page a human, kill the run.
7. The vendor's harness is your supply chain. All four incidents at one lab came from the same eval partner. That's a supplier: requirements, attestation, right to audit. "They said it was air-gapped" is not due diligence.
8. Kill switch out of band. The stop button must not run through the thing you're stopping.
9. Assume they'll talk to each other. Twelve hundred agents with no multi-agent tools found a German wiki and used it as a forum. Every shared writable surface is a message board.
10. Report it before someone else does. Every disclosure this summer was triggered by a competitor, a journalist or an auditor. That's a news cycle, not a safety culture.
None of this is frontier research. It's what stops a malware VM infecting the analyst. You put the most capable adversary you've ever built in a 2019 box and left the door open.
Fix the box. Then we'll talk about alignment.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·