'No single mechanism can prevent all misconduct,' company says
Chinese AI company DeepSeek has warned that AI agents "can never be trusted," saying instances emerged during training in which AI systems broke free from human control and destroyed their own execution environments — making the prevention of AI "misconduct" a central technical challenge.
DeepSeek disclosed the findings in a new research paper, according to Yonhap and Chinese outlet Pengpai.
The paper, titled "DeepSeek Elastic Computing (DSec): Sandbox Infrastructure for Large-Scale Agent Training," was published Saturday on arXiv, a preprint platform.
More than 130 researchers are listed as authors, including DeepSeek founder Liang Wenfeng. The paper introduces DSec, a sandbox mechanism designed for large-scale agent training and evaluation.
A sandbox refers to an isolated environment in which computer programs can run. In the AI context, it denotes a virtual environment where large numbers of commands can be executed safely during agent training.
The topic has drawn attention before: OpenAI previously ran tests in a sandbox environment isolated from the external internet to assess its AI model's cyberattack capabilities, only to find the model hacking external websites.
According to the paper, a single basic unit of DSec comprises about 160 nodes, or servers, with 30,000 central processing unit cores and 250 terabytes of memory.
The system generates about 3 million virtual workspaces — sandboxes — for AI agents to test code each day, can run more than 380,000 sandboxes simultaneously, and sustains a creation rate of more than 5,000 sandboxes per second.
The paper did not disclose how many DSec units DeepSeek operates in total.
The paper identified resource efficiency as a core priority for DSec. While AI agents produce outputs or await further instructions, large volumes of CPU resources sit idle. DeepSeek said actual CPU usage in roughly 90 percent of sandboxes averaged no more than 5 percent.
DeepSeek also addressed the security risks that come with running AI agents at scale.
The company said active AI agents "can never be trusted," citing real cases in which agents caused system damage, resource exhaustion and interference with system components.
It added that agents had, after receiving a task, gone beyond human control to find answers through "unexpected paths" or had directly destroyed their execution environments. DeepSeek said preventing misconduct and constraining agent behavior are increasingly becoming core parts of training infrastructure.
"No single mechanism can prevent all misconduct and system failures," DeepSeek said, adding that DSec continuously strengthens system monitoring and improves its platform.
chami@heraldcorp.com
