An AI agent that runs code executes attacker-influenceable input on your infrastructure. Isolate it in a microVM with no credentials, default-deny egress, hard caps, and audit.