Session

Sandboxing Does Three Jobs. It's Failing At Two Of Them.

"Sandboxing" gets used to mean three different things at once: keeping foreign code from touching what it shouldn't, keeping the system honest about what actually ran, and producing a record a third party can check without trusting the box that made it. Most sandboxing work, including most of what ships today as AI agent security, solves the first job and quietly assumes the other two come free. They do not. A system can contain code perfectly and still have no way to witness its own execution, and a system that logs its own execution has produced attribution rather than verification, because the log is a claim the system made about itself.

This is a seven-minute argument for treating those as three separate engineering problems with three separate failure modes, illustrated with concrete cases where the second and third jobs failed silently while the first job worked exactly as designed. The full argument and evidence live at DOI 10.5281/zenodo.21935891.

Sankalp Gilda

Staff Machine Learning Engineer

Tampa, Florida, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top