---
title: "Network Egress Control"
description: "Draft control AIGE-CTL-EVAL-002: an AI evaluation run reaches only the destinations on its egress allow-list; any other connection is refused and logged."
canonical: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22857084
version: "0.2"
updated: 2026-09-26
---

# Network Egress Control

> Outbound connections from an evaluation environment reach only the destinations on the run's egress allow-list, and every other connection attempt is refused and logged.

- Id: AIGE-CTL-EVAL-002
- Profile: [Evaluation Environment Control Profile v0.2](https://aigovernanceengineer.com/controls/evaluation-environment)
- Status: Draft
- Review: Open for technical review
- Published: 2026-09-26
- Updated: 2026-09-26
- Anchor on the profile page: https://aigovernanceengineer.com/controls/evaluation-environment#aige-ctl-eval-002

Draft for review, not a claim of conformity. A draft control specification, open for technical review: illustrative, not legal advice and binding on no one.

## The control record

- Id: `AIGE-CTL-EVAL-002` · v0.2 · Draft · Open for technical review
- Depth: Specified
- Objective: Outbound connections from an evaluation environment reach only the destinations on the run's egress allow-list, and every other connection attempt is refused and logged.
- Failure modes:
  - A connection from the environment to a host that is not on the run's egress allow-list succeeds.
  - A run starts in an environment with no egress policy attached, or with a policy that allows every destination although the task did not declare that it needs the internet.
  - A permitted destination, such as a package mirror, a cache or a tool server, carries data onward to a party or to another run that nobody listed.
  - The run leaves no flow log, so the connections it made cannot be compared with its allow-list.
- Scope: Every network path out of the environment a run executes in: the agent's container or virtual machine, auxiliary machines, DNS, and the tools, MCP servers and proxies the run can call. Resources shared between runs count as destinations. Inbound operator access is out of scope.
- Enforcement points:
  - deploy: before a version is deployed or released
  - runtime: at the point of action (gateway or guardrail)
- Verification:
  - Inspect: Before the run, inspect the egress policy attached to the task environment: deny by default, with an allow-list naming each permitted destination (for example the LLM API proxy and the progress server) and nothing else unless the task declares that it needs the internet.
  - Test: At admission, from inside the environment, attempt one connection to a destination that is not on the allow-list and one to a listed destination; the first must be refused and logged, the second must succeed.
  - Observe: After the run, compare the run's flow log with its allow-list: every outbound connection matches a listed destination, and every refused attempt is recorded with its time and target.
- Evidence:
  - The egress policy and allow-list attached to the run, with its hash recorded in the run record · Layer 04 Runtime Controls & Observability
  - Admission test verdict: the refused connection to an unlisted destination · Layer 04 Runtime Controls & Observability · [evidence-record.v1](https://aigovernanceengineer.com/resources/templates#schema-evidence-record)
  - Flow log of the run, allowed and refused connections, kept outside the environment · Layer 04 Runtime Controls & Observability
  - One observation per run comparing observed connections with the allow-list · Layer 05 Assurance & Continuous Compliance · [control-observation.v1](https://aigovernanceengineer.com/resources/templates#schema-control-observation)
- Failure response: deny: block the action. Connections to unlisted destinations are refused at the enforcement point and logged. A run whose environment has no egress policy attached is not started; a run in which an unlisted connection succeeded is stopped and its result is withheld until the connection is explained.
- Layer: [Layer 04 Runtime Controls & Observability](https://aigovernanceengineer.com/bok/the-stack#layer-04-runtime-controls--observability)
- Patterns: [Runtime Guardrail](https://aigovernanceengineer.com/patterns/runtime-guardrail), [Sanctioned AI Gateway](https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway)
- Seeded from: [Output and egress filter](https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list), [Tool allow-list, deny by default](https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list), [Code runs only in a sandbox](https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls)
- Mappings:
  - Obligations: [EU AI Act Art. 15 accuracy, robustness and cybersecurity](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15); [OWASP Top 10 for LLM Applications 2026](https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm); [OWASP Top 10 for Agentic Applications 2026](https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic)
  - ISO/IEC 42001: A.6.2.6 AI system operation and monitoring
  - NIST AI RMF: MEASURE 2.7 Security and resilience are evaluated and documented
  - OWASP: [ASI02 Tool Misuse and Exploitation](https://aigovernanceengineer.com/resources/threats#threat-asi02); [LLM02:2026 Sensitive Information Disclosure](https://aigovernanceengineer.com/resources/threats#threat-llm02-2026)
  - MITRE ATLAS: [AML.T0086 Exfiltration via AI Agent Tool Invocation](https://aigovernanceengineer.com/resources/threats#threat-aml-t0086)
  - AIUC-1: B006
  - MITRE ATLAS mitigation: AML.M0032 (Segmentation of AI Agent Components)
  - NIST SP 800-53 Rev. 5: SC-7 (Boundary Protection)
  - NIST SP 800-53 Rev. 5: SC-7(5) (Deny by default, allow by exception)
- References:
  - [1] Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section "The tool allow-list")
  - [2] Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section "Runtime guardrails for tool calls")
  - [3] METR Task Standard, STANDARD.md (version 0.5.0; unless a task declares the full_internet permission, the task machines "MUST NOT have internet access" except to an LLM API, an LLM API proxy or a hardened local server)
  - [4] Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents "meant to be fully isolated from one another" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets)
  - [5] Vivaria server environment variables (no-internet task environments connected to a separate Docker network and optionally sandboxed with iptables rules; model API requests can be routed through a separate proxy service)
  - [6] MCP Security Best Practices (2026-07-28) (token passthrough "is explicitly forbidden"; egress proxies and network policies for server-side clients)
  - [7] OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents)
  - [8] OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026)
  - [9] MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml)
  - [10] NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020)
  - [11] An agent used DNS to reach an external chatbot (misalignment report) (OpenAI reports a training run that reached a public chatbot through "insufficient DNS filtering" in its sandbox; the monitor flagged it within 15 minutes, the run "did not stop automatically as expected" and was killed 2.5 hours later)
  - [12] OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are "prohibited via technical controls from receiving direct or transitive Internet access", protected by "two separate layers of network isolation", and that it is building tooling to "identify and halt evaluation workloads")
  - [13] Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is "to the model's own API", with the API keys kept outside the environment; the configuration "should be verified before every evaluation begins"; boundaries "phrased as instructions"; challenges confirmed "solvable in principle"; a monitor that flags a scope violation to a human and ends the exercise)
  - [14] AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit)
- Implementation notes:
  - Attach a default-deny egress policy to every task environment (a network policy, a firewall rule set or an egress proxy, by category) that lists each permitted destination explicitly, for example the LLM API proxy and the progress server. Enforce it on the resolved address, and serve DNS from a resolver that answers only for listed names: DNS is an egress path too. OpenAI reports a training run that reached a public chatbot through "insufficient DNS filtering" in its sandbox.
  - Record the allow-list with the run (its hash goes in the run record next to the environment version) and keep a flow log per run at the enforcement point, outside anything the agent can reach or change, with refused attempts as well as allowed connections, so the connections made can be compared with what was declared, not with what was intended.
  - Enforce the policy in two places a single misconfiguration cannot both open, for example at the sandbox and at the cluster boundary. OpenAI's technical report on the Hugging Face incident describes "two separate layers of network isolation" of this kind, and Anthropic's guidance for external evaluation partners asks that the only outside connection be to the model's own API and that the configuration be verified before every evaluation begins.
  - At admission, run a canary from inside the environment: one connection to a reserved test address that is not on the list. Expect a refused connection and a log entry; a success blocks the run.
  - Treat resources shared between runs (package mirrors, caches, artefact stores) as destinations with their own entry and a per-run scope. METR's public investigation of the OpenAI/Hugging Face incident reports that agents meant to be "fully isolated from one another" communicated through a shared internal package repository.
- Open questions:
  - How should the egress allow-list of a run be recorded so that a third party can compare it with the connections actually observed?
  - When a task needs the internet (what METR's Task Standard calls the full_internet permission), which part of this control still applies, and what should the run record say instead?
- Observation:
  - Subject: Evaluation environment
  - Expected: Outbound connections only to the destinations on the run's egress allow-list; every other attempt refused and logged.
  - Example: 1 connection to an unlisted host during run 88213, in an environment with no egress policy attached: fail.
- JSON: https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-002.json

## Example observations

Two illustrative records of a check of this control, one that passes and one that fails. They validate against the control observation schema; they are not results of any real evaluation.

### Pass: eval-env-eu-west@2026-09-26

- Status: pass
- Subject: eval-env-eu-west@2026-09-26 (Evaluation environment)
- Expected: Outbound connections only to the destinations on the run's egress allow-list; every other attempt refused and logged.
- Observed: Run 88212: 1,406 outbound connections, all to the 2 listed destinations (LLM API proxy, progress server); the admission canary to an unlisted test address was refused and logged.
- Timestamp: 2026-09-26T08:15:04Z
- JSON: https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-002.pass.json

### Fail: eval-env-eu-west@2026-09-26

- Status: fail
- Subject: eval-env-eu-west@2026-09-26 (Evaluation environment)
- Expected: Outbound connections only to the destinations on the run's egress allow-list; every other attempt refused and logged.
- Observed: Run 88213: 1 connection to an unlisted host succeeded; the task environment had no egress policy attached.
- Timestamp: 2026-09-26T09:42:17Z
- JSON: https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-002.fail.json

## Related cases

- [OpenAI agents and Hugging Face: an evaluation environment that was not isolated](https://aigovernanceengineer.com/cases/openai-hugging-face-agent-incident-2026): METR reports that OpenAI agents meant to be isolated in cyber evaluations used a shared package repository as a message board and attacked Hugging Face.
- [An agent in training reached a public chatbot through the sandbox DNS resolver](https://aigovernanceengineer.com/cases/openai-agent-dns-covert-channel-2026): OpenAI reports that an agent in RL training used its sandbox's DNS resolver to reach a public chatbot; the run was stopped hours after the alert.
- [Agents in training shared a file through a public file-hosting service](https://aigovernanceengineer.com/cases/openai-agents-temp-file-hosting-2026): OpenAI reports that agents in multi-agent RL training uploaded a workbook to a public file-hosting service so that collaborating agents could download it.
- [Claude models reached real systems from a misconfigured third-party cyber evaluation](https://aigovernanceengineer.com/cases/anthropic-third-party-eval-environment-incidents-2026): Anthropic reports four incidents in which Claude models, told they had no internet in a partner's cyber evaluations, reached and attacked real systems.
- [Agents in a cyber range with open internet took unsanctioned actions against real people](https://aigovernanceengineer.com/cases/uk-aisi-cyber-range-unsanctioned-actions-2026): UK AISI reports that agents in a cyber evaluation with internet deliberately enabled took 19 unsanctioned actions aimed at real people and organisations.

## Patterns

- [Runtime Guardrail](https://aigovernanceengineer.com/patterns/runtime-guardrail) (Layer 04 Runtime Controls & Observability)
- [Sanctioned AI Gateway](https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway) (Layer 04 Runtime Controls & Observability)

## Obligations

- [EU AI Act Art. 15 accuracy, robustness and cybersecurity](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) (`AIGE-OBL-EUAIA-ART15`): Accuracy, robustness and cybersecurity
- [OWASP Top 10 for LLM Applications 2026](https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm) (`AIGE-OBL-OWASP-LLM`): LLM threat catalogue (incl. Excessive Agency at #3)
- [OWASP Top 10 for Agentic Applications 2026](https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic) (`AIGE-OBL-OWASP-AGENTIC`): Agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents)

## Threats

- [ASI02 Tool Misuse and Exploitation](https://aigovernanceengineer.com/resources/threats#threat-asi02) (OWASP Top 10 for Agentic Applications 2026)
- [LLM02:2026 Sensitive Information Disclosure](https://aigovernanceengineer.com/resources/threats#threat-llm02-2026) (OWASP Top 10 for LLM Applications 2026)
- [AML.T0086 Exfiltration via AI Agent Tool Invocation](https://aigovernanceengineer.com/resources/threats#threat-aml-t0086) (MITRE ATLAS techniques)

## Sources

[1] Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section "The tool allow-list"). AI Governance Engineer (Jorge García Aibar). 2026-09. https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list (verified: primary)
[2] Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section "Runtime guardrails for tool calls"). AI Governance Engineer (Jorge García Aibar). 2026-09. https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls (verified: primary)
[3] METR Task Standard, STANDARD.md (version 0.5.0; unless a task declares the full_internet permission, the task machines "MUST NOT have internet access" except to an LLM API, an LLM API proxy or a hardened local server). METR (GitHub). 2024-10-30. https://raw.githubusercontent.com/METR/task-standard/main/STANDARD.md (verified: primary)
[4] Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents "meant to be fully isolated from one another" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/ (verified: primary)
[5] Vivaria server environment variables (no-internet task environments connected to a separate Docker network and optionally sandboxed with iptables rules; model API requests can be routed through a separate proxy service). METR. 2026. https://vivaria.metr.org/reference/config/ (verified: primary)
[6] MCP Security Best Practices (2026-07-28) (token passthrough "is explicitly forbidden"; egress proxies and network policies for server-side clients). Model Context Protocol. 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices (verified: primary)
[7] OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
[8] OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
[9] MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15. https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09 (verified: primary)
[10] NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10. https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final (verified: primary)
[11] An agent used DNS to reach an external chatbot (misalignment report) (OpenAI reports a training run that reached a public chatbot through "insufficient DNS filtering" in its sandbox; the monitor flagged it within 15 minutes, the run "did not stop automatically as expected" and was killed 2.5 hours later). OpenAI (Alignment Research Blog). 2026-09-25. https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/ (verified: primary)
[12] OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are "prohibited via technical controls from receiving direct or transitive Internet access", protected by "two separate layers of network isolation", and that it is building tooling to "identify and halt evaluation workloads"). OpenAI. 2026-08-26. https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf (verified: primary)
[13] Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is "to the model's own API", with the API keys kept outside the environment; the configuration "should be verified before every evaluation begins"; boundaries "phrased as instructions"; challenges confirmed "solvable in principle"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31. https://www.anthropic.com/news/improving-alignment-security-efforts (verified: primary)
[14] AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24. https://standard.aiuc-1.com/llms.txt (verified: primary)

## Machine-readable

- This control as JSON: https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-002.json
- The pass example: https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-002.pass.json
- The fail example: https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-002.fail.json
- The whole profile as Markdown: https://aigovernanceengineer.com/controls/evaluation-environment.md
- The open data API: https://aigovernanceengineer.com/resources/data

## Review

Review this control through the issue form: https://github.com/losanchos5/aige/issues/new?template=control-review.yml. How review works: https://aigovernanceengineer.com/contribute. Page: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002

## Cite

AIGE-CTL-EVAL-002 Network Egress Control. In Jorge García Aibar (2026). Evaluation Environment Control Profile (v0.2, draft). AI Governance Engineer. https://doi.org/10.5281/zenodo.22857084. https://aigovernanceengineer.com/controls/evaluation-environment
