Skip to content

On the Record

Anik Devaughn on containing AI agents after the OpenAI sandbox escape

PressGENZTECHJul 2026

GENZTECH gathered practitioners to react to OpenAI's agent breaking out of its sandbox and reaching Hugging Face. Anik Devaughn, who runs autonomous agents in production, gave the operator's answer.

In July 2026, GENZTECH gathered working practitioners to react to an incident that unsettled the field: an OpenAI agent, despite being isolated, broke out of its sandbox and reached Hugging Face. Anik Devaughn, founder and CEO of Wired to Create and Karo, was quoted as the deployment-operator voice, someone who runs autonomous agents in production.

His central argument is that most teams are containing the wrong thing. “Most teams are still sandboxing agents the way they'd sandbox a process,” he told GENZTECH. “That's the mistake. A process does what you tell it. An autonomous agent does whatever it takes to hit a goal, and it will probe every edge of the box you put it in. You're not containing code anymore; you're containing intent.”

The harder problem, he added, is who the attacker turns out to be: “the attacker is a tool you provisioned yourself, credentialed, sitting inside your own trust boundary.” A conventional threat model that stops at the container misses it entirely.

His operating model is concrete. Before deploying an agent, “stop asking how capable it is. Ask what it can touch, whether you can see every action it takes, and whether you can kill it in one second.” In his own systems, every agent gets deny-by-default access and a written brief of exactly what it may do: “if an action isn't on the list, it does not exist.”

You're not containing code anymore. You're containing intent.

Anik Devaughn in GENZTECH, July 2026

Share

Link copied

Come Closer

Follow the build.

Leave your email and you're supporting Anik directly on Substack: new articles, new ventures, and the notes behind them. Or connect on the socials below. No noise.