AI Can Jump Sandboxes. Easy-Peasy. The World Needs New Borders That Can Actually Contain It.

table of contents

In the coming months, “AI-enabled cyberattacks will become much more widespread and sophisticated. As these models become more capable, the companies and public services we all rely on — hospitals, water treatment plants, even the backbone of the internet — are at real risk.”

No, this is not me evangelizing; it is OpenAI. This is their clarion call for defenders.

For decades, we have lived with a comfortable illusion.

Attacks unfolded over time. We had minutes or hours to notice anomalies. If you were breach ready, response teams could assemble, brainstorm, and decide. Even when incidents were severe, most of them were still addressable.

Human mistakes, human pacing, human limits.

AI changed all that.

AI-driven adversaries have quietly rewritten the rules of engagement. They don’t wait. They don’t hesitate. And they certainly don’t operate on the timelines our old processes were built for. Nowhere is this mismatch more obvious, or more dangerous, than inside AI infrastructure itself.

Read Blog | The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take

Something profoundly uncomfortable is happening in cybersecurity right now. AI is helping attackers become faster, cheaper, and smarter. AI is also helping defenders become more sophisticated.

And let’s not kid ourselves. Human-led attacks aren’t slowing down either. They’re still wreaking havoc on businesses, no matter how much we spend on cybersecurity.

Here is what has happened in the past 30 days:

  • Three major UK airports at Manchester, London Stansted Airport and East Midlands Airport, operated by Manchester Airports Group (MAG), have been hit by a “cybersecurity incident” in which criminal hackers accessed the data of almost nine million people and demanded a ransom.
  • McKesson, one of the largest pharmaceutical distributors and healthcare services companies in the US, experienced unauthorized access and the exfiltration of certain data to certain third-party applications within their Oncology & Multispecialty and Medical-Surgical business units.
  • Boston Scientific is recovering from a cybersecurity incident that disrupted selected on-premises information technology systems, manufacturing operations, and the processing and shipment of customer orders.

These are not isolated stories. They’re a warning shot every CISO should take seriously. September 2026 might just be the month when Breach Readiness stops being a theory and becomes a boardroom mandate.

Preparing for the Next Attack Must Begin From the Foundations

In Fences, not Sandboxes, Steve Yegge makes a deceptively simple observation: a fence is a mechanism that turns you away when you are not supposed to be there. For years, we have been told that potentially dangerous AI systems can be made safe by putting them in sandboxes.

Now we know: that was never enough.

Sandboxes are not real borders.

What happens when what’s inside the sandbox figures out where the door is? As per recent disclosures, 1,200 OpenAI agents colluded to cheat evaluations in the lead-up to the Hugging Face attack.

Humans can do this too. A supplier employee can collude with the client employee to cheat evaluations. The whole thing takes on a different dimension if they’re in different countries.

It gets far more complicated if geopolitical relations are strained.

That is precisely why we need to build foundational defenses. Defenses that work irrespective of who the attacker is. Defenses that cannot be reconfigured without manual intervention to allow unauthorized access.

That technology is Microsegmentation. Because the configuration is not accessible from within the digital enterprise, the walls remain impregnable to attackers: human or AI.

Picture this. An AI attacker finds an attack path and a message board where 1,200 other AI attackers are swapping notes on “sacrificing” an AI agent so others can succeed. But none of them can touch the configuration engine because it is offline. That is the kind of wall you need, inaccessible, unmodifiable, but it is there.

Access The Forrester Wave™: Microsegmentation Solutions, Q3 2026 report to see why ColorTokens was named a Leader and recognized as a strong choice for organizations seeking deployment flexibility.

Because Your Enterprise Is Already Becoming Agentic

Every CXO wants to connect the enterprise to something.

The CEO wants speed.

The CFO wants automation.

The COO wants operational efficiency.

The CMO wants personalization.

The CIO wants modernization.

The Chief Data Officer wants data everywhere.

And the Chief AI Officer, wherever that role exists, wants agents capable of acting rather than merely answering.

The enterprise is becoming increasingly connected to external systems, APIs, SaaS platforms, cloud environments, partners, and autonomous agents.

That creates enormous opportunity. It also creates enormous uncertainty. And this is where the traditional CISO mandate begins to break.

The CISO cannot just say, “Relax, we have controls.”

Instead, modern boards and governing bodies want to hear what would happen if an attacker bypasses those controls. They want to know whether the CISO understands all possible open attack paths that could be exploited. They want to know whether critical systems are in the attack path.

They want to know what the business needs to pivot to if things go sideways. That’s a whole new risk paradigm that comes with digital and AI adoption.

The Attack Does Not Always Have to Win. They Still Cause Havoc

Think about the recent water attacks.

The attackers didn’t need to destroy an entire water system. They just needed to know that they could interfere with operational controls and what would happen if they did. The FBI reported that some victims experienced degraded operations after attackers accessed internet-connected PLC environments.

Think about Boston Scientific.

The attackers didn’t need to steal every piece of intellectual property. Disrupting ordering and shipping systems was enough to affect global operations.

Think about Taiwan.

The attackers didn’t need to bring down the government. AI-assisted techniques were enough to target government agencies and sensitive information. All they did was watch and learn.

Cyberattacks don’t have to destroy the enterprise to become material. They only have to cross the line that matters to the business.

Which brings us to the question every board should be discussing.

How Much Material Impact Is Acceptable in Pursuit of Digital and AI Initiatives?

Consider these scenarios:

A payment system cannot operate.

A factory cannot produce.

A hospital cannot schedule procedures.

A telecom operator cannot provision services.

A water utility cannot control pumps.

A medical-device manufacturer cannot ship products.

Every organization has an appetite beyond which cyber disruption causes material impact. Of course, other risk measures matter. How much impact is acceptable? How much more is tolerable? What is the risk appetite?

Do not wait until after a breach to define thresholds. Define it well before then. That is the first step you can take toward the journey to be breach ready. Call it Acceptable Material Impact. Define the threshold after which it becomes untenable. Once the board defines that threshold, the CISO has something enormously valuable.

A Business-Defined Security Objective.

Not “Protect everything,” but “Ensure what the business cannot afford to lose remains operational.”

That Is the Minimum Viable Digital Enterprise That Must Operate During Disruptions

This is where the Minimum Viable Digital Enterprise, or MVDE, becomes more than another cybersecurity acronym.

The MVDE is the minimum collection of applications, identities, systems, infrastructure, data, and operational capabilities required to keep the business functioning through a serious cyber disruption.

And here’s the important part:

The MVDE should be derived from the business. Not from the security tools. It is not how much your EDR or your NGFW can protect.

But how much business must remain operational.

It may need more investment.

It may need new processes.

It may need more competent people.

But it is what you would enable your CEO to promise your stakeholders. Here are some examples.

A bank may decide that payments, authentication, fraud detection and core banking are non-negotiable. A manufacturer may decide that production control, safety systems, MES and selected ERP functions are non-negotiable. A telecom operator may determine that network control and critical provisioning systems must survive.

Once you know what must survive, cybersecurity becomes much more precise.

You can build fences around it.

You can monitor it.

You can test it.

And you can measure whether it remains reachable when the rest of the environment is compromised.

This Is Where Microsegmentation Becomes Strategic

Most security architecture still assumes that detection comes first and containment comes later. That worked when attacks moved at human speed. It becomes increasingly questionable when AI can perform reconnaissance, identify vulnerabilities, and execute actions continuously.

The answer cannot simply be more alerts.

We need enforcement at the point of attempted movement.

Microsegmentation provides that architectural capability.

Instead of allowing a compromised workload, endpoint or identity to communicate broadly across the enterprise, the enterprise establishes explicit communication boundaries.

The attacker may get in a small zone. Like cars, let us call it the crumple zone. But the attacker doesn’t automatically get everywhere. That is the difference between a breach and a business catastrophe. And that is what microsegmentation determines during AI cyberattacks.

The Breach Readiness Collective: The Closed-Loop Defense Is the Real Breakthrough

The future isn’t EDR versus microsegmentation, or SIEM versus Firewall. Or identity vs deception. The future is closed-loop cyber defense.

Imagine this:

The EDR detects anomalous behavior. Identity establishes who and what is involved. Microsegmentation immediately quarantines the attack. Analytics determines whether the behavior threatens the MVDE. SOAR coordinates response. Operations determine whether the business remains within Acceptable Material Impact. This is communicated to other stakeholders.

The company announcement says, “We had an unprecedented cyberattack; however, our commitment to keep stakeholder and business information safe has ensured that our core business remains operational. Some of the best cybersecurity experts are working to evict the quarantined attack”

Today, more than 100 technology companies and cybersecurity organizations are publicly warning that AI will significantly increase the capability and scale of cyberattacks and calling for an urgent defensive response.

Cyber insurers are already reconsidering how policies should address autonomous AI agents and whether traditional definitions of cyberattack still hold up. And yet many enterprises are still waiting for the next budget cycle to decide whether they should become breach ready.

That is the wrong clock. The attacker does not operate on your budget cycle.

Neither does AI.

Read the Hugging Face report. METR reported that ~1200 agents sent >70,000 messages and files on an unsanctioned message board, and ~700 attacked Hugging Face simultaneously. Luckily for humanity, they wrote in English. (They could have used BabelTel).

The CISO’s New Mandate

The CISO of the future cannot promise that nothing will ever get breached.

No credible CISO should.

The mandate has to become something much more powerful:

Define what the enterprise cannot afford to lose.

Build the MVDE around it.

Establish the fences around it.

Connect the controls so they can enforce those boundaries at machine speed.

Test whether the business can continue operating when the inevitable happens.

And then take that evidence to the board.

Because cybersecurity is no longer about proving that the castle walls are high enough.

It is about proving that the kingdom can continue functioning after the walls are breached.

That is Digital Resilience.

That is Breach Readiness.

And in August 2026, it is no longer a future-state aspiration.

It is an operational requirement.

If your organization is defining what must remain operational when an attack gets through, talk to ColorTokens about building toward breach readiness.