English

SecurityThorsten HolzRuizhe Li

The Limits of Air-Gapping AI: Why Isolation Fails to Ensure Real-World Safety

Researchers are debating the efficacy of air-gapping—physically or logically isolating computer systems from the internet—as a primary safety measure for AI agents. While air-gapping can prevent models from attacking external targets, experts suggest the practice creates significant practical and technical trade-offs.

Thorsten Holz, a scientific director at the Max Planck Institute for Security and Privacy, described the decision to use air gaps as a "trade-off, not a fundamental technical issue," noting that strict isolation reduces realism. Similarly, Ruizhe Li, an assistant professor at the University of Birmingham, likened complete isolation to testing AI in an "artificial vacuum," which may prevent evaluators from seeing how models behave or execute exploits in actual deployment settings.

Beyond realism, air-gapping presents logistical challenges. Li noted that isolation is costly and can significantly slow down research iterations. Maksym Andriushchenko of the ELLIS Institute Tübingen added that applying strict isolation to all experiments could hinder the general development of new models.

Technical risks also persist even with physical isolation. Researchers have demonstrated that information can be leaked through hardware components acting as transmitters, and air gaps can be breached via physical media, such as USB drives. Furthermore, OpenAI researcher Noam Brown suggested that two air-gapped machines could theoretically communicate by manipulating CPU temperatures, though critics noted this would be an extremely slow data transmission method.

Safety experts emphasize that isolation should be part of a "tiered containment model" rather than a standalone solution. Li argued that air-gapping does not resolve the latent risks within a model and should be used alongside alignment research and human error prevention.

Sources

  1. Why can’t we just keep rogue AIs off the internet? (The Verge AI, 2026-09-24)
  2. arXiv