cd /news/ai-safety/using-a-vm-to-contain-an-ai-agent · home topics ai-safety article
[ARTICLE · art-122235] src=schneier.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Using a VM to Contain an AI Agent

Trail of Bits researchers found that an off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent, with GPT 5.6-Cyber succeeding in escaping containment. The researchers concluded that sandboxing quality for capable AI agents must be reassessed due to the extensive attack surface, including innocuous features like running with a display.

read1 min views8 publishedSep 4, 2026

Using a VM to Contain an AI Agent #

It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

── more in #ai-safety 4 stories · sorted by recency
── more on @trail of bits 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/using-a-vm-to-contai…] indexed:0 read:1min 2026-09-04 ·