Using a VM to Contain an AI Agent
It won’t work:
My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.
An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.
Tags: AI, cybersecurity
Comments
lurker • September 4, 2026 2:49 PM
So, a sandbox is actually a box made of sand.
Subscribe to comments on this entry
Leave a comment
LoginName
URL:
Remember personal info?
Fill in the blank: the name of this blog is Schneier on ___________ (required):
Comments:
Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/
Notify me of new posts by email.
Sidebar photo of Bruce Schneier by Joe MacInnis.








English (US) ·