Bottom line: Ptacek considers sandbox escapes and network hacking by open AI models technically feasible, but criticizes weak isolation rather than lacking frontier models.
Security expert Thomas Ptacek argues that already available open-weights models from 2025 could perform sandbox escapes and network scans in a pentest setup. The problem is less about AI capability than insufficient sandboxing procedures.
Thomas Ptacek, a renowned security researcher, positions himself clearly against the assumption that only cutting-edge frontier AI models are suited for complex attack patterns such as sandbox escapes and network penetration. In his assessment, an open-weights model from 2025 equipped with an appropriate pentest harness would be capable of performing such attacks in most real-world network environments.
Ptacek attributes the surprising perception of such attack scenarios to the fact that organizations assume sounder — that is, more robust — sandbox implementations than actually exist. This points to a fundamental problem with isolation and containment strategies, not a technical barrier of the AI models themselves.
For CISOs, this sharpens the reality: security against AI-driven attacks cannot rest solely on the assumption of complex, hard-to-access models. Instead, network architecture, segmentation, and sandbox mechanisms must be made significantly more robust — regardless of what type of models could potentially be deployed as attackers.
Source: simonwillison.net · Published July 23, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.