Secure your Mac or PC
Your computer holds more than the files an AI agent needs for a task. It may also contain private messages, saved browser logins, photographs, financial records, and work documents. A safer setup gives the agent a limited workspace without automatically giving it access to the rest of your digital life.
Run the agent in a restricted environment, such as a container, without administrator access to the host computer. Give it only the files and tools it needs, and keep control of its permissions and security settings outside its reach. A dedicated virtual machine is another option. Avoid sharing your entire home folder, personal browser sessions, password manager, or unnecessary clipboard access. Check what the environment can actually reach; its label alone does not prove isolation. Container security guidance explains why permissions and shared files matter.
Let the agent propose system changes for you to review through a separate administrator account. Keep your operating system and isolation software updated, and retain built-in malware protection, disk encryption, and the firewall. Disk encryption helps protect a lost or stolen computer; it does not prevent an authorised process from reading files while you are logged in.
Restrict the agent environment’s connections separately from your normal browsing. Start without general internet access, then allow only the services needed for the task. Block unnecessary access to other devices on your network. If you need remote administration, use a private remote-access service, such as Tailscale, and restrict access to approved people and devices. Check that the same access is not also exposed through ordinary Wi-Fi or Ethernet.
Keep passwords and recovery keys outside the agent’s workspace. Use an external password manager for your own credentials, and limit any service credentials to the permissions the task requires. Avoid placing secrets in prompts, project files, or logs. Credentials stored on the same physical computer may still be exposed if that computer itself is compromised. OWASP provides further credential guidance.
Be selective about connected tools. Email, browsers, cloud storage, and deployment systems each give the agent more ways to affect your life. Grant access for a specific purpose, and require clear approval before sending messages, publishing work, or deleting shared information. Review important results; isolation does not make the agent’s judgement reliable. OWASP’s agent-security guidance covers these decisions.
Maintain encrypted backups with older versions that the agent cannot overwrite or delete, and practise restoring them. Keep important activity records outside its control. Recheck restrictions after upgrades, restarts, and network changes. Before leaving an agent unattended, set resource and spending limits, check power and sleep settings, and make sure you can stop it.