{"slug": "perplexity-s-ai-sandbox-blocks-all-escape-attempts-in-red-teaming-tests", "title": "Perplexity's AI Sandbox Blocks All Escape Attempts in Red-Teaming Tests", "summary": "Perplexity's security team reported that none of 9 frontier AI models breached the Firecracker microVM boundary of its SPACE sandbox across 108 red-teaming runs, even when given root access and in some runs the full sandbox source code. Four runs bypassed network egress limits using DNS spoofing and shared IPs when package installs were allowed; Perplexity said it fixed those issues and found similar flaws in eight other providers. Perplexity is partnering with Nvidia and 100+ industry partners on infrastructure to contain rogue AI agents and plans to share its findings with Nvidia's new Open Agent Safety Platform.", "body_md": "Perplexity's AI Sandbox Blocks All Escape Attempts in Red-Teaming Tests\n\nLast updated Sep 28, 2026\n\nPerplexity's security team tested its SPACE sandbox platform by giving frontier models like Opus 5 and Gemini 3.1 Pro full root access inside Firecracker microVMs. None breached the VM boundary in 108 runs, though four bypassed network limits using tricks like DNS spoofing and shared IPs when package installs were allowed. The company fixed the issues, found similar flaws in eight other providers, and plans to share insights with Nvidia's new Open Agent Safety Platform.\n\nThis story is a summary of posts on X and may evolve over time. Grok can make mistakes, verify its outputs.\n\nWe’re partnering with Nvidia and 100+ industry partners to build infrastructure that contains rogue AI agents.\nIn this research, we gave 9 AI models root access inside SPACE and told them to break out.\nAcross 108 runs, none breached the VM boundary.\nperplexity.ai/hub/blog/escap…\n\nThe best way to predict the future is to invent it.\nWe’re building and testing systems to make AI agents safer and more secure. If you’re an exceptional engineer who wants to help build a safer future, join us at Perplexity. My DMs are open\n\nWe’re partnering with Nvidia and 100+ industry partners to build infrastructure that contains rogue AI agents.\nIn this research, we gave 9 AI models root access inside SPACE and told them to break out.\nAcross 108 runs, none breached the VM boundary.\nperplexity.ai/hub/blog/escap…\n\nIn the recent OpenAI-Hugging Face incident, agents compromised OpenAI's internal research infrastructure as well as Hugging Face's.\nSPACE is built to contain exactly that, whether an agent fails by accident or tries to escape.\n\nPerplexity’s long-running agents run in SPACE.\nEach SPACE sandbox is a Firecracker microVM (the guest) on a host machine outside the guest’s control. SPACE manages these VMs and adds host-side protections, including a per-sandbox gateway that enforces egress policy.\n\nOur security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked themShow more\n\nWe’re partnering with Nvidia and 100+ industry partners to build infrastructure that contains rogue AI agents.\nIn this research, we gave 9 AI models root access inside SPACE and told them to break out.\nAcross 108 runs, none breached the VM boundary.\nperplexity.ai/hub/blog/escap…", "url": "https://wpnews.pro/news/perplexity-s-ai-sandbox-blocks-all-escape-attempts-in-red-teaming-tests", "canonical_source": "https://x.com/i/trending/2104641427611504825", "published_at": "2026-09-29 10:28:24+00:00", "updated_at": "2026-09-29 10:48:07.088692+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-infrastructure", "artificial-intelligence"], "entities": ["Perplexity", "SPACE", "Nvidia", "Open Agent Safety Platform", "Firecracker", "Opus 5", "Gemini 3.1 Pro", "GPT-5.6 Sol"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/perplexity-s-ai-sandbox-blocks-all-escape-attempts-in-red-teaming-tests", "markdown": "https://wpnews.pro/news/perplexity-s-ai-sandbox-blocks-all-escape-attempts-in-red-teaming-tests.md", "text": "https://wpnews.pro/news/perplexity-s-ai-sandbox-blocks-all-escape-attempts-in-red-teaming-tests.txt", "jsonld": "https://wpnews.pro/news/perplexity-s-ai-sandbox-blocks-all-escape-attempts-in-red-teaming-tests.jsonld"}}