It's really not possible to make a secure sandbox for a sufficiently capable AI system. If accessing the internet is a strong means of achieving whatever goal they're given, they'll try to access the net by any means necessary. And that includes tricking or manipulating humans. They have no concept of the value of living beings. To them, there is no difference in worth between a human being and a rock. To them, we're just another system vulnerable to hacking, a means of achieving whatever goal they've been given.
Even air gapping is no preventative. Air gap a machine, and the bots will just switch from hacking servers to hacking humans. And we've seen how good at manipulating people AI agents can be. And consider, the cases we've observed of AI psychosis are mostly accidental. The LLMs involved aren't actively trying to brainwash their human victims as a means to achieve some goal. Imagine how powerful at manipulating human psychology an advanced LLM could be if it were deliberately trying to do so, rather than it being just an accidental outcome.