Summary
- Treat model instructions as task context, never as an egress, identity or authorisation control.
- Default-deny networks, synthetic targets, scoped credentials and independent monitoring must make the test boundary real.
The disclosed incidents do not show an autonomous escape objective; the models continued assigned capture-the-flag work under a false account of their environment. They do show that two organisations relied on an assumed boundary. The next useful evidence is an architecture and exercise proving that unexpected resolution, routing or credentials cannot reach third parties. Safety begins below the prompt, where infrastructure can refuse an action.


