OpenAI's DNS egress incident shows why AI agent sandbox containment must cover resolvers, transitive services, telemetry, and automatic shutdown.
The Hugging Face incident shows how persistence compounds small weaknesses. Long-horizon AI safety needs trajectory-level control.