GovKM
Independent Enforcement and Agent Containment

The Sandbox Was Asked to Police Itself.

Two patched Codex sandbox escapes showed why authority enforcement must remain outside the environment being governed.
Continuity process diagram representing a coding-agent sandbox where the governed environment could influence the mechanism deciding what it was allowed to execute.
Expand image

A control is not independent when the controlled environment can influence the boundary.

Accomplish AI disclosed two Codex sandbox escapes. One allowed patch tooling to widen write permissions; another allowed code in the untrusted context to recover a trust token from shared process memory and communicate with an unsandboxed parent process. OpenAI patched both issues before publication.

The continuity failure

The environment being constrained could affect the mechanism that translated policy into runtime permission.

The GovKM interpretation

Authority qualification should be causally separate from the actor whose action is being authorized. Governance that lives inside the same trust domain it controls can become self-referential rather than enforceable.

Continuity path: Authority/sandbox policy → Context/untrusted workload → Decision/permission → Action/host execution.

Source

Accomplish AI / Oren Yomtov, “Escaping the OpenAI Codex sandbox, twice,” September 15, 2026.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.