A new arXiv paper examines what it calls the containment gap in deployed agentic AI frameworks.

The core concern is that agents are no longer isolated text generators. They can use tools, call services, and affect external environments, which makes public-facing safety requirements harder to satisfy.

For builders, the paper is a warning that agent safety cannot be added only at the prompt layer. Frameworks need stronger containment, permissions, and operational controls.