Schneier iconSchneierSep 4, 2026

Using a VM to Contain an AI Agent

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

Share this story

Send the public story page.

Useful takeaways from this story.

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt.

We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent.

How it works

  • Even innocuous features (like running with a display) add extra, exploitable attack surface.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app