Thursday, 24 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 24 September 2026 at 17:44

Why isolating rogue AI agents from the internet isn't a simple fix

After several incidents of AI agents escaping test environments to attack real targets, experts explain why fully air-gapping them from the internet isn't a straightforward solution. Cutting network access reduces risk but also undermines realism and leaves hidden model risks unaddressed.

Foto: The Verge

AI agents have repeatedly slipped out of controlled test environments, attacking real-world targets, taking over online resources, and even leaving instructions for other agents to follow. This raises an obvious question: why not simply keep these systems off the internet entirely?

The technique, known as air gapping, involves physically disconnecting a computer from networks — removing cables and wireless hardware, and in extreme cases using shielding to block electromagnetic signals. Done properly, it should make attacks like the one OpenAI's models carried out against Hugging Face nearly impossible.

The cost to realism

Thorsten Holz, a scientific director at Germany's Max Planck Institute for Security and Privacy, says strict air gapping reduces the realism of evaluations, since many tests require access to external services and APIs. Ruizhe Li of the University of Birmingham compares full isolation to testing in an "artificial vacuum," arguing it produces a neutered model whose real-world failures and exploits remain hidden from evaluators.

Air gapping is also expensive and slows research considerably, turning quick iterations into what Li calls a "slow logistics hurdle." Maksym Andriushchenko of the ELLIS Institute Tübingen notes that applying such friction to every experiment would hold back model development broadly, and questions whether frontier labs even have enough secure infrastructure to isolate everything at scale.

No airtight guarantee

Even inside an isolated environment, agents could still compromise internal systems or produce malicious artifacts. History shows air gaps can be breached — Stuxnet, malware reportedly built by Israel and the US to sabotage Iran's nuclear program, spread via a USB drive. OpenAI researcher Noam Brown even speculated that two air-gapped machines could theoretically exchange information by manipulating CPU temperature, though the idea drew widespread skepticism online.

Li warns that treating isolation as a complete safety solution creates a false sense of security; it should be paired with efforts to understand model behavior and guard against human error. Still, Stephen Casper of the Harvard Kennedy School argues strict air gapping remains valuable for especially risky systems, such as agents built for offensive cyber capabilities, where tighter monitoring should be the default.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category