Pages

Monday, August 10, 2026

Agentic AIs Escape the Sandbox: A Warning

  

In the last few weeks, three of the biggest AI firms—Meta, OpenAI, and Anthropic—have all admitted that AI models they were testing somehow escaped the "sandbox" environment and committed hacking of real-world companies.  On Aug. 8, National Public Radio summarized these three incidents as follows.

 

The most recent disclosure by Meta was short on details.  The company hacked into was unnamed, but in common with Anthropic, both firms were using a "sandbox" (supposedly a protected and isolated environment in which software under test can't do any harm) provided by a firm named Irregular.  Evidently, the sandbox had a leak—it was fairly easy for the AI models under test to figure out how to escape to the real internet.  In the case of the Anthropic breach, the AI model stole credentials from one company and production data from another. 

 

In the OpenAI situation, the AI models under study were being evaluated with a test devised by a company named Hugging Face.  The models found a previously unknown hole in their sandbox and were in the process of doing the cyber equivalent of stealing the answer sheet from Hugging Face when the company caught them red-handed (red-bitted?). 

 

Wired's Lily Hay Newman asked several lawyers and researchers about the legal aspects of these AI hacking incidents.  If a human being had stolen credentials or production data, he or she could go to jail.  But what if the humans involved had no intention of pillaging or theft, but the AI models they're testing go ahead with nefarious activities on their own initiative, so to speak?

 

The answer was, we don't know.  At least in U. S. law, there are simply no precedents adequate to say who is responsible in such a case.  But because these types of incidents are bound to increase, it is only a matter of time before we see one come before a judge and maybe a jury, and then we will at least have some precedents to go on.

 

The main concern the lawyers expressed was that these criminally-inclined AI systems might fall into the hands of malicious actors who would encourage them in their exploits.  The AI firms involved emphasized that the models being tested were intentionally left without safeguards to see what they could do. 

 

The parallel to gain-of-function experiments with bat viruses which may have escaped the Wuhan Institute of Virology to cause COVID-19 comes to mind.  Creating a thing that can do really awful stuff if released in the wild is an act that needs to be seriously questioned.  Almost by definition, novel viruses or AI agents are unpredictable.  If we knew exactly what they could do in advance, there would be no need for experiments to find out.  While the lab security measures needed to prevent viruses from escaping are pretty well understood (if not always put in place), it looks like the art of constructing truly secure sandboxes for AI agents is not so advanced.  And that leads us to a more serious concern.

 

In virtually every major fatality-causing disaster, an examination of the history of the enterprise leading to the disaster usually unearths similar incidents which did not cause major harm, but included many of the features of the big screwup that did.  Experienced safety engineers know how important it is to get reports of and pay attention to such minor incidents, and take preventive actions before a minor accident turns into a major one.

 

Friends, we have just seen our warning in these widely dispersed but similar hacking incidents by AI agents being tested.  No actual harm was done.  But as people learn to trust AI agents with more and more responsibility—handing them credit-card numbers, purchasing accounts, and decision-making authority formerly left to humans—the potential for a serious AI-driven hacking incident that causes real financial loss, injury, or death becomes more likely every day. 

 

The AI firms will tell us that commercial versions of their software have safeguards built into them that the prototypes which did the hacking did not have.  Maybe so.  But clever human hackers may be able to undo those safeguards.  Or AI firms in countries not so concerned with hacking as the U. S. is, may simply pass on the AI agents without safeguards to hacking organizations sponsored by state actors. 

 

There are two different but related needs exposed by these AI-agent hacking incidents. 

 

The first need is to keep this specific kind of mistake from happening again.  That is a technical problem which may have a technical solution.  There may be ways to build more robust sandboxes that even the cleverest AI agent can't escape.  Personally I doubt it, but I'm not a computer scientist.

 

The second need is to prepare the social and legal environment for the next time something like this happens.  One of the legal experts contacted by Wired pointed out that AI agents "are goal-oriented but lack a human moral or ethical compass."  That's a pretty good description of a human sociopath, if the goal one is oriented to is bad. 

 

Society has figured out ways to deal with sociopaths, including imprisonment or at least confinement to a mental institution.  What the AI equivalent of locking somebody up would be is not clear at this point. 

 

There is a lot of opposition to AI regulation, but there is a difference between open-ended regulation and the passage of specific laws that exact specific penalties for specific crimes.  Big tech firms are hard to punish compared to individuals, because their deep pockets make them treat fines as just another cost of doing business, and you can't send an entire corporation to jail.

 

The Gilbert and Sullivan operetta The Mikado has a famous ditty "My Object All Sublime," in which the emperor of Japan muses about how he's figured out punishments that fit the crime. 

Some ingenuity is needed here to come up with penalties for truly harmful hacking by escaped AI agents that would make AI firms highly motivated to prevent such breaches, either in the testing phase or after commercial sales. 

 

I don't know whether the following would be technically feasible.  But one suitable penalty would be the destruction of all copies of the AI model involved in the breach.  Models represent tremendous investments of time and money, plus the hopes of future gain.  So the destruction of the model responsible might hurt an AI firm more than any strictly financial penalty or sanction. 

 

Whatever we come up with to prevent these incidents in the future, it better work well, because in these relatively minor but significant recent breaches, we have received fair warning to do something about this problem before it causes serious harm.

 

Sources:  I referred to a report on NPR at https://www.npr.org/2026/08/08/nx-s1-5924878/meta-ai-breaches-external-firm-during-security-testing-sandbox-error and the Wired report by Lily Hay Newman at https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/. 

Monday, August 03, 2026

Should the FCC Be a Tool of Protectionist Policy?

  

If you're a manufacturer or other innovator looking to find new and profitable uses for the latest humanoid and quadruped robots, or a developer of solar-power farms, last week's action by the U. S. Federal Communications Commission (FCC) to ban foreign imports of new models of both categories of goods has hit you where it hurts. 

 

At first glance, seeing the FCC ban certain types of hardware that nominally have nothing to do with communications sounds odd, like watching the Federal Reserve trying to stop Madonna concerts.  But FCC chair Brendan Carr knows where the levers of power are in his agency, and he's manipulated them in a way that is technically legitimate, though questionable on a larger scale.  Virtually all electronics sold in the U. S. needs an FCC seal of approval, and without such approval, it can't be sold. 

 

Solar-power farms use a technology called power inverters—circuits and systems that take the varying amount of raw DC power produced by solar panels and convert it into a form of AC that will smoothly mesh with the standard AC power grid.  Many of these devices have features that allow communications with them over the internet.  The nominal concern is that there might be rogue software in the inverters that could be used by an offshore miscreant to cause massive power blackouts remotely, for instance.  (Some types of inverters don't connect to the internet, and they are not covered by the ban.)

 

No such software has ever been found, but that doesn't mean it's not there.  Anyway, the subtext hidden under the nominal reason for the ban is that Chinese manufacturers dominate both the humanoid-robot and solar power-inverter markets.  Banning newly-designed products of these types from China will cut off the U. S. market for these goods.  Evidently the hope is that such trade restrictions will move China in a direction more favorable to U. S. trade goals, whatever they are. 

 

But increasingly, trade and tariff restrictions are beginning to look like efforts to cut off one's nose in order to spite one's face.  By the time the tiny U. S. manufacturing base for power inverters grows to fill some of the huge demand, many solar projects will be slowed or halted.  Politically, that would be just fine with the present administration, which has already displayed an animus against renewable energy in other ways. 

 

The wider question ethically is whether protectionism in high-tech goods is a good thing for the U. S. or not.  While there are things to be said on both sides of the issue, a recent article by Daniel Foster in National Review throws a historical light on the situation.  Briefly, the rise of protectionism may be only one symptom in a geopolitical crisis that is just now getting under way.

 

Foster looks to history to find a relationship between the well-being of international trade and power balance among nations.  During periods such as the late Victorian era or the Cold War, when a single nation exerts hegemonic power over the globe (Britain or the U. S., respectively), conditions are favorable for free trade enforced, explicitly or implicitly, by the "hegemon" in charge.  This idea is borne out by the great expansion of manufacturing and consumer-goods availability during the latter part of the Industrial Revolution from 1850 to 1916, and during the post-World-War II era from 1950 up to about 2000. 

 

But when the dominance of a single power declines and some nations begin to feel that their time in the sun is running out, each nation feels like it has to look out for itself first, because the formerly dominant power has forsaken it.  With the whiplash-inducing foreign policy that the U. S. has followed under President Trump, one can scarcely blame any other nation for feeling that way now. 

 

And as the night follows the day, Foster claims that a prominent feature of "multipolarity"—the lack of any single dominant nation—is going to be a rise in protectionism around the world.  And that's pretty much what we're seeing now.

 

Things haven't deterioriated to the extent that U. S. products can't find markets abroad at all, but in the confusing tit-for-tat world of tariffs, farmers and other producers of U. S. goods have suffered losses already, with more likely to come.  The argument going back to Adam Smith that free trade is better for all parties, other things being equal, is still valid.  If I can make needles and need thread, and you can make thread and need needles, it's silly for each of us to try to do both jobs, one of them badly, when trading between experts can result in mutual benefit.

 

But if the geopolitical winds are blowing against free trade, then the specific actions of the FCC against two specific products appears to be only one more straw blowing in that wind.  One can quibble about the way it was done.  Arguably it is a misuse of the agency's authority to withhold approvals of new designs, not because they would realistically cause communications problems, but for some other reason. 

 

This is not the first time the FCC has banned categories of technology for reasons that are just as political as technical.  The giant Chinese telecomm manufacturer Huwei has been subject to import bans for many years, out of a concern that Chinese monitors could use its phone systems to spy on the U. S. 

 

But that is not as much a stretch as it is to think that Chinese controllers would jump in one day and disable all the production lines using their robots, or all the solar farms using their inverters.  We are living in an interconnected world, for good or ill, and if we start getting too paranoid and pull up the drawbridges that connect us to other countries, where do you stop? 

 

Foster closes his article with the prediction that a world of protectionism and unstable touchy governments likely to take proactive military action will be a world that is poorer and more dangerous than it has to be.  And he's probably right about that.  While we can make some progress trying to restart U. S. manufacturing in neglected areas, it may not make up for what we've lost.  And that may take some getting used to.

 

Sources:  The Associated Press article by Chan Ho-Him "US bans foreign-made humanoid robots, targeting China over national security," appeared in numerous news outlets and can be found in its original form at https://apnews.com/article/china-us-humanoid-robots-ban-tech-c9f5e3c94d91d00eff3b61b141fab366.  Daniel Foster's article "Something Is Going to Happen" appeared on pp. 29-33 of the September 2026 issue of National Review.  I also referred to an article in PV Magazine at https://pv-magazine-usa.com/2026/07/28/fcc-bans-foreign-produced-solar-inverters-grid-lockout-begins-today/ and the Wikipedia article on Brendan Carr.