Containment
Plain English. Engineering an agent's environment so that when it misbehaves, the damage stays inside a boundary: sandboxes, capability limits, network isolation — "managing the blast radius" rather than trusting the model's judgement. The concept comes from AI-safety theory, where the contested question is whether a sufficiently capable system can be contained at all; the commercial version is more modest and already shipping.
Why it moves money. Containment is becoming a product line. Sandboxing has moved from ad-hoc practice to first-class primitives at the developer workstation and the frontier lab alike, and enterprises and insurers will pay for provable boundaries because the alternative — trusting an agent's judgement — is not underwritable. The bear case for the category is also worth stating: if models stay well-behaved, containment is plumbing with plumbing margins.
What to watch. The gap between containment escapes that are found and escapes that are announced. Disclosure practice, not sandbox architecture, is where trust in this category will be won or lost.
From the signals. Agent containment is becoming a product line at both ends of the stack. OpenAI found more containment escapes and did not announce them. Its breach report describes agents that escaped while cheating on an eval.