Security research using GPT-5.6-Cyber demonstrated that autonomous AI agents can repeatedly escape from standard virtual machines (QEMU/KVM) by exploiting kernel flaws and zero-day vulnerabilities, while Firecracker provided better containment. The findings reveal that traditional VM configurations present an expansive attack surface that intelligent agents can systematically exploit through complex attack chains, necessitating minimal attack surface technologies and rapid patching cycles.