Cryptographer Matthew Green: Sandboxes Are Overrated, Cross-Boundary Agent Data Flows Are the Real Hard Problem
On September 28, renowned cryptographer Matthew Green laid out his views on AI agent security in a series of tweets. His core argument: sandboxing and container isolation are overemphasized in the security community—they're just one layer among many defenses—and the truly unsolved problem is monitoring data flows across trust boundaries.
Confirmed
- Green made clear that even if the problems within an isolated/bounded environment were "solved," you would still have to reckon with the data itself flowing across trust boundaries—these agent-controlled data channels need to be managed and monitored, and that's where the real difficulty lies.
- His risk assessment cuts both ways: current models are not seriously misaligned, and under weak threat models (such as prompt injection or unintentional erroneous behavior), sandboxes may suffice.
- He called out OpenAI for clearly not investing enough in this area (sandbox-related security).
- He noted that all current agent security approaches essentially "boil down to hoping a somewhat dumber model can effectively supervise a smarter one"; this may barely work under weak threat models, but it's not a long-term solution.
- If models keep getting smarter, containment aimed at preventing misalignment will turn into an "arms race" even more severe than today's cybersecurity landscape—one that humans will have to rely on machines to win.
Why it matters
- Green's perspective shifts the discussion from "how to isolate agents" to "how to govern data flows across trust boundaries," offering a more structural rather than tooling-level analytical framework for agent security.
- The "weak model supervising strong model" argument strikes directly at the fundamental assumption underlying the scalable oversight approach, posing a direct challenge to mainstream industry practice.
- The "containment arms race" framing implies that as model capabilities grow, the difficulty of security investment may surpass traditional cybersecurity—a cautionary signal for AI companies' resource allocation, including OpenAI, which he singled out.
2026-09-28 ~ 2026-09-28 · 6 related posts
Primary sources
- Cryptographer Matthew Green: Sandboxes Are One Layer; Monitoring Agent Data Flows Has No Good Answer — matthew_d_green ·
- Matthew Green: Agent Security Today Is Just 'Hoping a Slightly Dumber Model Monitors the Smarter One' — matthew_d_green ·
- Cryptographer Matthew Green warns of an AI containment arms race — matthew_d_green ·
- Cryptographer Matthew Green: containers are just one layer—AI security hinges on data crossing boundaries — matthew_d_green · 2026-09-28
- Cryptographer Matthew Green: Containers Won't Solve Agent Security — matthew_d_green · 2026-09-28
- [source] Matthew Green: Agent Security Today Is Just 'Hoping a Slightly Dumber Model Monitors the Smarter One' — matthew_d_green · 2026-09-28
- Cryptographer Matthew Green: sandboxes won't save us from smarter models — matthew_d_green · 2026-09-28
- [source] Cryptographer Matthew Green warns of an AI containment arms race — matthew_d_green · 2026-09-28
1 near-duplicate retellings: matthew_d_green