Zero Egress CAGE
Ali Emre Yenihayat, Berk Ülker · Team Zero Egress CAGE
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
The July 2026 incident showed isolated environments fail via permitted egress. We present CAGE-1: a pre-run containment gate with 13 auditable controls. A CLI verifies evidence integrity, successfully blocking regressions in tests. CAGE-1 converts containment promises into checkable evidence.

Reviews
I like the idea of attesting for containment policy, but I'm not sure it would have stopped cases like the HF incident where the configuration really did require exposure of the vulnerable Artifactory server.
The text submitted reads more as a technical report than as a paper, with a lot of highly dense information (tables, lists) and not a lot of explanations, high-level descriptions, or discussions.
CAGE-1 takes a smart DevSecOps approach to AI containment by shifting enforcement to a pre-run gate with 13 auditable controls. Providing a CLI tool that verifies configuration evidence and catches regressions in tests delivers immediate practical utility. However, because it operates primarily as a pre-flight check, its main blind spot is runtime state drift or in-session escalations (e.g., an agent modifying network routes post-boot). Pairing this static pre-run gate with continuous below-the-guest telemetry would make it far more comprehensive
Cite this project
@misc{yenihayat2026zero,
title = {{Zero Egress CAGE}},
author = {Ali Emre Yenihayat and Berk Ülker},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/zero-egress-cage-w71t}},
url = {https://apartresearch.com/sprints/projects/zero-egress-cage-w71t}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …