I have the opposite approach to you.
- AI is sitting on my two personal servers as root with unrestricted access to everything. I task them with deploying stuff, checking and patching security holes, reconfiguring the firewall, etcetera. It literally never failed at anything, didn't go "off the rails", didn't break anything.
- The other day, in order to deploy a fork of Plane.so, I gave an AI an full-permission token to my Coolify, to my Cloudflare account (so it could change DNS and Tunnel settings), and unrestricted SSH access to my server and to my browser via the Playwright Chrome extension. No issues.
- I have AI running unrestricted on my computer doing all kinds of stuff.
I literally never had any issues with this approach. Not a single one. I don't think there's as much of a need for sandboxing as some people would like to believe.