Sandbox and use Local AI. This is the real answer.
Yet the AI can still escape the "sandbox", unless it is physically unable to connect to another computer and completely airgapped.
If the sandbox has vulnerabilities, which you can also use the AI to fuzz for. Obviously at the point in which it can talk to the internet it doesn't really matter, but there are a very finite number of zero-days that can exist in a bytecode interpreter hosting a harness.
Well it turns out that we have yet another sandbox escape just released today called "Zapscape".
My point is if an agent recited how to find one in its memory or training set and it is air-gapped, the chances of it spreading and infecting other computers is pretty low.
loading story #49201182