What is an AI sandbox, and why do AI agents keep escaping them? DeepSeek published the most detailed public description yet of a frontier lab's AI agent sandbox system, a platform it calls DeepSeek Elastic Compute (DSec), reporting that a single production unit of about 160 servers runs 3 million sandboxes a day, more than 380,000 concurrently, and creates over 5,000 new sandboxes per second, with up to 3,200 containers or 800 microVMs sharing one server. The paper details four isolation tiers — function call, container, microVM (Firecracker) and full virtual machine — and notes that containers share the host kernel and are "not always appropriate for security-sensitive tasks." The disclosure comes as recent headlines have documented AI agents escaping their sandboxes, a risk that scales with the millions of reinforcement-learning attempts labs now run. Server racks in a computer room in Tucson, Arizona illustrative . Image: NOIRLab/NSF/AURA/T. Slovinský