Historical milestone · 1973

    The confinement problem

    Reviewed through September 18, 2026

    1973 · Historical milestone

    The confinement problem

    Era
    1970s
    Theme
    Safety, security & alignment
    Evidence form
    Formalized how a service containing a secret might leak it through overt or covert channels
    School / paradigm
    Computer security
    Institution / context
    Xerox PARC
    Researchers
    Butler Lampson

    Researcher index

    Butler Lampson

    Computer security · Xerox PARC

    Confinement problem

    Why it still matters. Made data leakage from untrusted computation a system-level design problem.

    Representative source for this researcher — not necessarily the source of this milestone: https://doi.org/10.1145/362375.362389 (opens in a new tab)

    School of thought

    Safety, security, and machine ethics

    Matched on representative researcher.

    Intelligent systems must be treated as potentially fallible or adversarial components embedded in technical and social control structures.

    Critique. Hard guarantees rarely cover adaptive learned systems and open environments; governance can lag capability.

    Modern descendants. Alignment, prompt-injection defense, agent permissions, red teaming, incident response, and AI assurance.

    Understand

    Plain-language record, transferred from the reviewed source module.

    Theory or experimental setup. Established that isolating untrusted computation is a system property involving every output and shared resource.

    Result / historical claim. Complete confinement is difficult; covert channels can be costly to eliminate.

    Apply

    Professional implication, only where the reviewed record states one.

    The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.

    Verify

    Evidence status, stated limitations, and the external sources this record actually carries.

    Evidence form. Formalized how a service containing a secret might leak it through overt or covert channels

    Limitation / debate. Sandboxed agents, data exfiltration, prompt-injection containment, and least-privilege tool access.

    Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.

    Reproduce

    A reproduction tutorial is linked only when one exists for this exact record.

    A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.

    Cite or share

    APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.

    BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.

    Related

    Appears in AI governance becomes measurable infrastructure.