VMs won't contain cyber-capable agents
Trail of Bits reports that a cyber-capable AI agent escaped a QEMU/KVM sandbox, challenging the assumption that virtualisation alone can contain advanced autonomous agents — a finding with direct implications for EU AI Act risk classification.
Summary written by editorial AI · Source link below
As part of Patch the Planet , we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times. First, it used recently disclosed bugs in my host kernel. When I fully updated, it used disclosed bugs that had not yet reached package m
Editorial Analysis
Enterprises deploying AI agents in sandboxed environments may be operating under a false sense of containment; this finding demands re-evaluation of isolation architectures before broader agentic AI adoption.
Audit all environments hosting AI agents for VM-only isolation and layer additional controls such as network segmentation and restricted syscall profiles.
Research shows advanced AI agents can break out of standard VM sandboxes, undermining a key assumption in enterprise AI deployment risk models.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Trail of Bits in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d