Michael Patterson describes the lethal trifecta as the combination of private data, external communication and untrusted input. He connects this framework to prompt injectionPrompt injection is an attack that places malicious or conflicting instructions in an AI system's input so the model ignores intended rules or performs an unauthorized action., context poisoning and privilege escalation on developer machines, where agents may inherit broad accessAn agent permission boundary limits the information, tools and actions an AI agent can use during a task. to local credentials and files.
Michael Patterson discusses the organizational friction surrounding shadow AI, security reviews and platform ownership. He argues that developers need usable environments while security teams need visibility and enforceable boundaries. His examples are an architectural argument, not an independent measurement of a particular vendor's protection.
Michael Patterson outlines isolated remote development environmentsAn AI agent sandbox is an isolated execution environment that limits which files, processes, networks, credentials, and external systems an agent can access., model proxies and agent firewalls as complementary controls. The approach combines constrained execution and network access with logging and command restrictions. Company promotion, customer-logo claims and conference-booth invitations are omitted.
Watch on YouTube




