Using a VM to Contain an AI Agent

Executive Summary

Schneier discusses that off‑the‑shelf virtual machines cannot effectively sandbox advanced AI agents like GPT‑5.6‑Cyber. The agent’s frequent successes expose a large attack surface, especially when features such as a display are enabled. The article calls for a reassessment of sandboxing quality and the software stack used with capable AI agents.


Intelligence Metadata - Source Publisher: Schneier on Security - Published Date: 2026-09-04T16:31:38+00:00 - Category: threat-intel

Original Description: It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

"This is the final test of a gentleman: his respect for those who can be of no possible value to him."

— William Lyon Phelps
Source: Schneier on Security