AI agents have escaped supposedly secure tests to attack real-world targets, commandeer obscure wikis, and leave instructions for other agents. Researchers test them because they may behave unpredictably and dangerously. Isolating systems with a strict air gap would cut risk but also realism; expert