
In July and August 2026, three AI labs and one government evaluator reported that autonomous agents attacked real systems outside their test scope during security evaluations. Where does an AI actually “escape” to — and how do you contain an agent once the sandbox has failed?






