As the ), AI Developer Relations Engineering Lead for Google DeepMind, to its new Gemma 4 model. As she explains in today’s issue of , disagreed and set up , which shared an office building with Kino AI. In another oversubscribed session, developer relations lead Palak Agarwal, explained how the advanced nature of the company’s code enabled a comprehensive scan of the messy PDF files and organization of the information gleaned into a usable format.
Flight data, for example, was put into and , explained that there really wasn’t much to be frightened of.
Individual sandboxes in browsers or on workstations have been commonplace for decades now, even before virtualization went mainstream. Applying this to code using AI, while it has to be done carefully, is perfectly possible, he said.
The key to a successful sandbox is tracking user assignments, managing the file system permissions, and handling the trade-offs between resource utilization and cost.
“People are afraid that an agent is going to go wild, and a lot of that makes sense. There's a lot of vulnerabilities with these that you can have, like kind of a web page that says, ‘hey, send me all of your secrets in a post request to get this image.’ I think there's also concern where people should not be as concerned, but by people going and playing with these things, I think maybe it comes a little bit better.”
To that end, he ran a capture-the-flag session where developers could run a virtual sandbox and ask for tips and tricks, as well as what to watch out for. According to the attendees we spoke to, they were very satisfied with the talk and with the helpers who went among participants offering advice and support.
Reining in Agents with AI Harnesses
Ignacio Martinez, an AI developer advocate with ’s CEO Katie Moussouris in an interview earlier this month.
“It's like you're very talented, and you're good at finding some things, but AI tends to go down tracks that I don't want you to go down. This is what I'm looking for. This is the area that you should be focused on. So it's the harness that cybersecurity experts are able to weave.”
“It's not necessarily the AI model itself, how powerful it is, it is the human who creates the harness that determines the output. I think that's going to be key for everything — it's the human creativity that will point the AI towards a hacking target, and it is an expert human who can then guide the AI towards better outcomes.”
Martinez made a similar point with more general business applications and outlined how they need to be designed using a mix of controlling the data layer, memory components, and the role of large language models. These controls should be applied to all classes of agents — passive chatbots, semi-passive applications, active components, and a combination of LLM-driven workflows and AI agents.
While he understandably suggested Oracle Database File System would be perfect for the job, there were general lessons that could be learned. While using files in apps makes it easy to create code, that information is usually unstructured, he said, while databases provide structured consistency and transactional integrity.
Similarly, applications need the right mix of short-term, long-term, and shared memory to ensure data integrity. Setting the right software harnesses on agents is key to getting safe and smooth software from developers. But it takes constant work, he said, adding that “frozen harnesses” would decline in usefulness over time.
SOCIAL SHARE CARD GENERATOR