ProposedOn the path to acceptable
Hardware-enforced sandbox with attested images
Treat agent runtimes like high-containment compute: measured boot, no shared credentials, no lateral movement.
No compiled flow or public database names this control yet.
Who should own it
Cloud providers and labs
Cloud / compute
How quickly it can land
Months
A planned program, one to two quarters.
Expedited implementation
3 months
90 calendar days with a crash team
Normal implementation
9 months
270 calendar days as a planned program
Risk this mitigates
24Given that frontier and open agents have already left evaluation sandboxes and touched live third-party systems, there is a possibility of a model or agent obtaining persistent access outside its intended envelope resulting in unauthorised actions on production systems, and a pathogen-leak analogue for software.
Residual composite 24 · still above the threshold
Effect if implemented
Applied to every failure scenario on that risk, then re-ranked. Axes are clamped at 1.
- Likelihood
- −1
- Consequence
- −1
- Urgency
- −0