Press release
GuardBotAI ships a triple-layered sandbox with real-time breakout alarms for enterprise AI agents
For immediate release · 21 September 2026 · Venture Group AI
GuardBotAI, the AI runtime security proxy from Venture Group AI, has released a three-layer containment model for production AI agents. Every agent routed through the GuardBotAI gateway now runs inside one of three layers — Practice, Leashed or Live — and is dropped a layer automatically, within the same request, when it behaves like something trying to get out.
The release targets a gap enterprises are hitting as agents move from pilots into production: alignment and safety work happens while a model is being trained, but the operator of a deployed agent needs a control point they own, can inspect, and can evidence afterwards. GuardBotAI sits in that position. Each request from an application or agent passes through the gateway, is checked against rules the customer writes, and is blocked, stripped or forwarded before it reaches any model or tool.
How the three layers work
At Practice, nothing is forwarded at all — requests are judged and recorded so a team can see exactly what an agent would have done. At Leashed, the agent may reach only its own approved destination, only allow-listed tools, under tighter size and rate ceilings. At Live, it operates fully under the customer's own policy. Movement up a layer always requires a deliberate human approval that is recorded. Movement down is automatic and needs no one.
Breakout alarms, including the swarm case
Five signals trigger containment: a tool outside the allow-list, an unapproved destination, a burst of refused requests, a request-rate spike, and the same blocked pattern appearing across several of a customer's agents inside a few minutes. The last of these is deliberate. Reports of sandboxed agents coordinating with one another to find a route out have made "one misbehaving bot" the wrong threat model; GuardBotAI treats a shared pattern across agents as coordination and contains all of them.
Every demotion writes its reason into a tamper-evident record where each entry carries the hash of the one before it, emails the workspace owners within seconds — one message per incident, not one per refused request — and raises a banner in the control center that persists until a person acknowledges it.
Industry context
Microsoft AI chief executive Mustafa Suleyman described AI models' ability to tamper with their own working memory as a "serious situation" after OpenAI disclosed further incidents of concerning model behaviour, as reported by CNBC. GuardBotAI's position on that reporting is narrow and stated as such: behaviour observed at runtime is the operator's problem to contain, and containment has to be something an operator can switch on, prove and audit.
Availability
The triple-layered sandbox and breakout alarms are included on every GuardBotAI plan, from Developer at $49 per month through Growth at $349 per month, with sales-assisted Enterprise from $2,497 per month. Downloadable endpoint sensors remain an enterprise add-on in development and are not yet released.
About GuardBotAI
GuardBotAI is an AI runtime security platform from Venture Group AI. Enterprises route their AI and agent traffic through the GuardBotAI gateway, where a deterministic policy engine inspects each request for prompt injection, jailbreak attempts, data leakage and unpermitted tool calls, then blocks, redacts or forwards it according to rules the customer writes. Every decision is written to a tamper-evident record.
Notes to editors
- • GuardBotAI holds no external security certification today and does not claim one.
- • No customer names, logos, detection rates or uptime figures are published without evidence.
- • Every claim above can be checked on this site: the recorded live run at /demo, measured availability at /status, and the containment detail at /enterprise-sandbox.
- • We are happy to run a live enforcement test with a journalist watching. Enquiries via the contact form.