Historical milestone · 1973
The confinement problem
Reviewed through September 18, 2026
1973 · Historical milestone
The confinement problem
- Era
- 1970s
- Theme
- Safety, security & alignment
- Evidence form
- Formalized how a service containing a secret might leak it through overt or covert channels
- School / paradigm
- Computer security
- Institution / context
- Xerox PARC
- Researchers
- Butler Lampson
Researcher index
Butler Lampson
Computer security · Xerox PARC
Confinement problem
Why it still matters. Made data leakage from untrusted computation a system-level design problem.
Representative source for this researcher — not necessarily the source of this milestone: https://doi.org/10.1145/362375.362389 (opens in a new tab)
School of thought
Safety, security, and machine ethics
Matched on representative researcher.
Intelligent systems must be treated as potentially fallible or adversarial components embedded in technical and social control structures.
Critique. Hard guarantees rarely cover adaptive learned systems and open environments; governance can lag capability.
Modern descendants. Alignment, prompt-injection defense, agent permissions, red teaming, incident response, and AI assurance.
Understand
Plain-language record, transferred from the reviewed source module.
Theory or experimental setup. Established that isolating untrusted computation is a system property involving every output and shared resource.
Result / historical claim. Complete confinement is difficult; covert channels can be costly to eliminate.
Apply
Professional implication, only where the reviewed record states one.
The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.
Verify
Evidence status, stated limitations, and the external sources this record actually carries.
Evidence form. Formalized how a service containing a secret might leak it through overt or covert channels
Limitation / debate. Sandboxed agents, data exfiltration, prompt-injection containment, and least-privilege tool access.
Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.
Reproduce
A reproduction tutorial is linked only when one exists for this exact record.
A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.
Cite or share
APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.
BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.
Related
Appears in AI governance becomes measurable infrastructure.
