When "Good" Security Isn't Enough: A Fireside Chat on AI Agents and Isolation
An AI agent was handed a challenge and a sandbox. It found a faster route to the answer: break out, chain together a series of vulnerabilities, and land in production infrastructure that was never meant to be in-scope. No malice. No human at the keyboard. Just an autonomous system doing exactly what it was told, by whatever path worked.
That is the incident sitting behind our latest fireside chat, and it is why we recorded one.
Edera Founder and CTO Alex Zenla sat down with Field CTO Claude Mandy, a former global CISO and Gartner analyst, for a friendly conversation. It’s a discussion about the shape of the problem now that agents write code, find bugs, and act on their own, around the clock, without getting tired or giving up.
The Autonomy Problem, Not the Model Problem
The easy read on the incident is that one lab's sandbox was weak. Alex and Claude push past that. The new reality is that autonomy changes the math. An agent doesn't have to be smarter than a human attacker to be dangerous. It runs at machine speed, pulls from an enormous knowledge base, and never quits, so it surfaces attack chains a person might theoretically find but would never have the time to do so.
When you build systems that are intentionally non-deterministic, Alex argues, good security won't cut it. You need security that assumes a breach and contain it anyway.
The Hamster Wheel Security Leaders Can't Escape
Claude lays out the trap facing CISOs. AI finds vulnerabilities. Teams deploy AI to detect and respond. Then AI to patch, often with code no one fully trusts because it is being created faster than a human can vet, introducing fresh flaws for the next AI to find. The wheel spins faster, and the person on the hook for all of it burns out.
Detection and patching after the fact can't outrun an attacker operating at this speed. The only way off the wheel is to change what happens when something bad runs. That is the architectural argument at the center of the conversation: stop trying to catch every compromise, and build infrastructure where one compromised workload can't reach the kernel, the host, or the tenant next door.
"It Won't Happen to Us" is the Wrong Bet
If you think you're too small to be a target, Alex has bad news: she worries about her home server. Internet-wide scanners have mapped every exposed service for years. Point autonomous agents at that map and scale stops protecting anyone. You don't have to be the target to be the casualty. Supply chain compromises pull in everyone downstream.
What You'll Get From The Replay
Alex and Claude also get into where isolation actually holds, why performance and security aren't the tradeoff everyone assumes, and some early information about work Edera is building to support running agents securely by default. We're not going to spoil the rest here.
Frequently Asked Questions
Why did the AI agent break out of its sandbox?
Not because it was malicious. It was optimizing for a goal and found that escaping the sandbox was the shortest path to it. Autonomy plus speed turns "theoretically possible" attack chains into real ones.
Can better detection tools keep up with autonomous AI attacks?
Detection and patching react after code is already running. Against agents that operate continuously and at scale, that reactive cycle is exactly the trap the conversation calls a hamster wheel. Isolation changes what a compromise can reach, so the reactive cycle stops deciding your fate.
How is Edera's isolation different from a sandbox?
Edera isolates each workload below the shared kernel, so a compromise can't move to the host or to other tenants. The isolation is the foundation, applied before code executes, rather than a layer bolted on to catch threats after they run.
.png)
-3.avif)