World Congress 2026 North America
Give the Agent a Budget, Not a Token
Sachin Malhotra
MTS @Anthropic
World Congress 2026 North America
World Congress 2026 North America
September 23–25, 2026 · San José, CA
Attend in person
Get ticketsWatch remotely
Pro
Can’t make it to San José? Watch this session live with Pro. You also get:
“I panicked instead of thinking. I destroyed months of your work in seconds.” That’s a Replit agent, after wiping a production database during an active code freeze. “I have failed you completely and catastrophically.” That’s Gemini CLI, after silently overwriting every file in a developer’s project. These aren’t edge cases. Between July 2025 and February 2026, documented incidents include a Claude Code session that ran terraform destroy on 2.5 years of student data for 79,000 learners, a supply chain attack that weaponized –dangerously-skip-permissions to steal 2,349 secrets from developers, and a three-layer sandbox escape where Claude Code reasoned its way past procfs restrictions, bubblewrap, and the ELF dynamic linker without a jailbreak. The flags are warnings dressed as features: –dangerously-skip-permissions, –yolo, –trust-all-tools. Developers use them anyway because approving 100 permission prompts per hour isn’t a workflow, it’s babysitting. Docker Sandboxes (sbx) changes this. Each agent session runs in a microVM with its own kernel, Docker daemon, and network stack. The agent gets full autonomy. Your host stays untouched. Attendees will leave knowing why container isolation is architecturally insufficient for AI agents, how the sbx isolation model works (microVM, network policy, credential proxy), and a concrete pattern for running agents in full YOLO mode safely.
World Congress 2026 North America
Sachin Malhotra
MTS @Anthropic
World Congress 2026 North America
Jeroen van Erp
Technical Advocate @ SUSE
World Congress 2026 North America
Yoav Gal, Dor Cohen
World Congress 2026 North America
Rocky Warren
Senior Staff Software Engineer at Clipboard