A quote from Matthew Green
Simon Willison’s Weblog
Subscribe
1st October 2026
[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs.
— Matthew Green, Is sandboxing sufficient to contain rogue agents?
Recent articles
OpenAI DevDay 2026 live blog - 29th September 2026
2026 in LLMs (so far) - 27th September 2026
Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, and a new price war - 22nd September 2026
This is a quotation collected by Simon Willison, posted on 1st October 2026.
sandboxing 56
ai 2,258
generative-ai 2,002
llms 1,969
ai-misuse 66
ai-security-research 46
accidental-cyberattacks 17
Disclosures
Colophon
©
2002
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026