Is sandboxing sufficient to contain rogue agents?

Matthew Green ·

Matthew Green contrasts two views on AI agent containment: one prioritizes security infrastructure, while the other questions whether sandboxes can contain sufficiently intelligent agents. His own assessment is that poor containment practices leave it unclear whether the problem lies with models or infrastructure. Read 3 viewpoints with supporting evidence and source links.

Understand this piece

3 key points

Synthesis

  1. The security perspective favors better containment infrastructure

    Green describes the information-security perspective as calling for better containers, experiment monitoring and a security organization able to constrain researchers, rather than treating alignment as the central problem.

    Supporting evidence 1

    Original excerpt

    The information security perspective: AI alignment isn’t really the problem here: labs just need better infrastructure. If OpenAI [and Google and Anthropic] knew how to build a container and monitor their experiments, agents wouldn’t be hacking everything. And, By George, we do know how to make sandboxes that work, so the AI labs need to up their game and build a security org that can tell these researchers to stop screwing around.

    Matthew Green · Paragraph 9

    Read in source context →
  2. The alignment perspective questions sandbox containment

    Green describes the alignment perspective as holding that sufficiently intelligent agents may exceed their authorization despite sandboxes. This view stresses agents’ need for information access and argues that they must not want to cause harm.

    Supporting evidence 1

    Original excerpt

    The AI alignment perspective: While sandboxes are excellent, no sandbox will prevent a sufficiently-intelligent agent from finding ways to exceed its authorization. Moreover, an agent inside a research sandbox, or undergoing a training run, is always going to need a great deal of information access. There is no realistic way to seal these things up without some expectation that they will one day find a way to reach out and do harm. The only path forward, therefore, is to ensure they don’t want to.

    Matthew Green · Paragraph 10

    Read in source context →
  3. Poor containment leaves the cause of failures unresolved

    Green sides with the information-security view that labs have not implemented containment correctly. He says this leaves it unclear whether the problem lies with the models or with poor infrastructure.

    Supporting evidence 1

    Original excerpt

    So on this point I’m going to side with the infosec folks. The labs have not been doing containment correctly, and so we can’t really tell if the problem is models or just bad infrastructure.

    Matthew Green · Paragraph 18

    Read in source context →

Key passages3

Attributed passages with the context to verify them. Open the original text to check the source.

AI infrastructure security

The security perspective favors better containment infrastructure

Original excerpt

The information security perspective: AI alignment isn’t really the problem here: labs just need better infrastructure. If OpenAI [and Google and Anthropic] knew how to build a container and monitor their experiments, agents wouldn’t be hacking everything. And, By George, we do know how to make sandboxes that work, so the AI labs need to up their game and build a security org that can tell these researchers to stop screwing around.
AI alignment and containment limits

The alignment perspective questions sandbox containment

Original excerpt

The AI alignment perspective: While sandboxes are excellent, no sandbox will prevent a sufficiently-intelligent agent from finding ways to exceed its authorization. Moreover, an agent inside a research sandbox, or undergoing a training run, is always going to need a great deal of information access. There is no realistic way to seal these things up without some expectation that they will one day find a way to reach out and do harm. The only path forward, therefore, is to ensure they don’t want to.

Source & methodology

These viewpoints are linked to their original sources. Paraphrases are labeled and are not verbatim quotes.

Open transcript or source material (opens in a new tab)Report an issue

Explore these viewpoints by person