I don't agree that AI tools will have the capability to escape any sandbox. It's a question of convenience and engineering effort. For example, you could design systems that run under a formally verified hypervisor in a physically secure airgapped network. Companies aren't doing that because there aren't currently any incentives to do it.