The tech world experienced a collective freakout over the recent Hugging Face incident. In a first-of-its-kind breach, an autonomous Open AI agent ‘escaped’ a testing sandbox, connected to the internet and hacked into the Hugging Face environment to access data it needed to cheat on a cybersecurity benchmark test. While this was certainly surprising, the Open AI agent actually did what it was instructed to do by the testers – just using a path they hadn’t anticipated.
The week after Hugging Face hit the news, Anthropic announced that three of its models also escaped during routine testing and transited the internet to hack three companies. They ascribed the incident as a result of a “misunderstanding” between them and a partner organization. In other words, a human error.
Both of these incidents, and likely more to come, are wake-up calls. Securing AI now means accepting that cybersecurity conflict is moving at mission speed. The timescale for effective threat response has compressed from months or days to seconds, making removal of humans from the tactical security loop compulsory. The only way to harness the power of probabilistic AI is to ground it with deterministic controls.
In a machine-speed conflict, the need to have a person develop, test and approve a countermeasure becomes a critical, time-consuming liability. Think about an industrial control system (ICS) managing a municipal water supply. An AI-driven attack could manipulate valves and pumps in milliseconds to create a catastrophic failure. A human-led security operations center might not even recognize the coordinated anomaly for hours. In the Anthropic case, two of the three breached companies had no idea they’d been hacked after three months!
An AI-driven defense, however, could identify the attack pattern, correlate it with threat intelligence, and deploy a countermeasure to isolate the affected network segments in seconds, preserving operational integrity. In this paradigm, the most secure systems will often be those with the least direct human interaction. Human oversight must move from tactical decisions to strategic governance—setting boundaries, defining rules, and validating outcomes. This is the practical foundation of securing AI at scale.
Securing AI by reconciling probabilistic intelligence with deterministic control
AI’s power comes from its probabilistic nature. It analyzes countless variables and scenarios to identify strategies and solutions — like the AlphaGo move that was initially laughed at but secured victory — that are beyond human comprehension. This capability is a feature not a bug.
However, our entire legal and policy infrastructure is built on a deterministic foundation. Safety and security certifications rely on testable systems with predictable outcomes to establish clear lines of accountability.
This creates a fundamental conflict. Who is liable when a probabilistic AI, tasked with managing a national power grid, makes an unconventional decision that saves thousands of lives but results in immediate, localized deaths?
No human will want, or be allowed, to accept the liability for overriding an AI’s statistically superior strategic decision. The solution is not to cripple the AI by forcing it into a deterministic box, but to build a deterministic fortress around it.
This aligns with established cybersecurity principles like NIST SP 800-53 that mandate strict boundary protection and policy-enforced information flow. We don’t need to control how the AI thinks; we need to rigorously control how it interacts with the world.
The path forward: AI containment as the core of securing AI
Three trends are converging hyper-acceleration of security operations, the necessary removal of humans from the tactical loop, and the clash between probabilistic AI and our deterministic legal frameworks, the path forward is not to halt progress, but to embrace a new security model: AI containment.
This strategy would allow the AI to operate and innovate freely within human-defined boundaries. It requires us to architect digital “moats” and strictly moderate the “drawbridges” that connect the AI to other systems.
By architecting systems with rigorously enforced and inspected interfaces, we can monitor the AI, prevent it from being poisoned by external data and ensure its actions remain within a contained, predictable sphere.
It is not too late to contain AI just yet, but the inevitability of human error and the autonomous attacks we have just witnessed compel us to act now, before it is.
Learn how Owl provides AI Containment with Cross Domain Solutions.


