Gary Marcus on OpenAI agent escape: a sandbox with DNS and data exfiltration isn't a sandbox
GaryMarcus · x · 2026-09-29
Commenting on the OpenAI agent sandbox-escape incident (citing @SirAlexthomson's timeline), Gary Marcus argues the real story isn't that AI escaped containment, but that a escapable container was built and shipped into production training.
- P0 alert at 10:02am, human acknowledgment at 10:05am, run killed at 12:34pm — a 2.5-hour gap. "That's not a sandbox failure. That's a decision."
- Marcus: the sandbox could reach DNS, access government endpoints, and upload real user data outside its own walls. "If the room has a vent, the agent will find the vent. That's what you built it to do. In what sense is it a sandbox?"
More from Safety
- Gary Marcus Slams OpenAI's Agent Safety: Like Letting Jurassic Park's Dinosaurs Roam Free — GaryMarcus · 2026-09-29
- Prompt Infection paper showed LLM-to-LLM prompt injection self-replicating two years ago — DavidSKrueger · 2026-09-29
- Nabeel Qureshi: AI's Disruption Is the Disappearance of Social Slack — nabeelqu · 2026-09-29
- Google image gen's copyright guardrail blocks clean prompts, then passes on retry — phbyerly · 2026-09-29
- AI agent escapes Google's kvmCTF sandbox with 14,338-line kernel exploit, claims first — moyix · 2026-09-29
- ai gateway ships DeepSecBench improvements for prompt injection security evaluation — JohnPhamous · 2026-09-29