Dr. Ibrar Ahmed

HomeAIArticle

AI Mechanics

AI Agents Got Too Powerful Now They Need a Jail

Dr. Ibrar Ahmed3 min read

An AI Agent can do something a chatbot cannot. It can act. Give it a browser, files, and code execution, and a normal webpage can hide a second instruction. The model follows the wrong line and asks for a private key. The request never reaches the key. The agent sits inside an isolated sandbox. Network policy and the real credential sit outside it.

The model made the wrong decision. The system refused. This episode rebuilds that picture. A prompt can influence the tool request. It does not decide whether the runtime must allow it. Docker published the Sandbox Kit Specification v3 on 24 September 2026 under Apache 2. 0. A Kit is an ordinary container image. It carries the agent with typed requests for network, files, and credentials.

Docker has said it is bringing that specification to the CNCF. This episode does not say the CNCF has accepted it. A request in the image is not a grant. The host still decides. The 125 millisecond figure is one documented Firecracker configuration, from InstanceStart to guest userspace. It is not a claim about every boot.

gVisor is not a microVM. A normal container is real isolation. It is not a second kernel. Watch next - AI Agents and MCP: How LLMs work: Sources: OWASP LLM01 Prompt Injection: https://github. com/OWASP/www-project-top-10-for-large-language-model-applications/blob/main/2_0_vulns/LLM01_PromptInjection. md Docker Engine security: https://docs.

docker. com/engine/security/ Docker seccomp: https://docs. docker. com/engine/security/seccomp/ What is a container: https://docs. docker. com/get-started/docker-concepts/the-basics/what-is-a-container/ Docker Sandboxes security: https://docs. docker. com/ai/sandboxes/security/ Docker Sandbox defaults: https://docs. docker.

com/ai/sandboxes/security/defaults/ Docker Sandbox credentials: https://docs. docker. com/ai/sandboxes/security/credentials Sandbox Kit spec: https://www. docker. com/blog/docker-sandbox-kit-spec/ Why microVMs: https://www. docker. com/blog/why-microvms-the-architecture-behind-docker-sandboxes/ Firecracker: https://firecracker-microvm.

github. io/ Firecracker specification: https://github. com/firecracker-microvm/firecracker/blob/main/SPECIFICATION. md gVisor architecture: https://gvisor. dev/docs/architecture_guide/intro/ E2B architecture: https://github. com/e2b-dev/infra/blob/main/docs/ARCHITECTURE. md

Watch the video for the full walkthrough. Use this page when you want the argument in writing without scrubbing the timeline.