Section 112 · Chapter 14, Frontier Safety and Containment
Testing Containment Systems
Every useful AI containment system has a paradox at the center: if the system is valuable, someone or something has to interact with it. Every interaction is a possible channel.
containment
What to do
- Start with a channel inventory.
- Ask whether the AI can persuade an operator to paste text into a tool.
- Ask whether generated code includes hidden network calls or dependency changes.
- Ask whether logs reveal secrets.
- Ask whether a timing pattern can transmit bits.
Evidence to preserve
- Preserve the inputs, versions, configurations, raw outcomes, and results for containment needed to reproduce work on Testing Containment Systems.
- Report results for containment by relevant slice, separate blocker failures from averages, state uncertainty and blind spots, and connect the result to a release decision.
Expert note
In a real release review, containment testing is a systems-security problem plus a human-factors problem plus an incentive problem. Treat the AI as a strategic actor if the risk model requires it.
Continue the conversation
Apply this to your context.
Save your product context once, then open a focused conversation that combines it with this concept.
Cite this page
Jason Arbon. "Testing Containment Systems." Testing AI Knowledge Edition, section 112.
https://jarbon.ai/testing-ai/knowledge/ch112-containment.html