← 深度专栏/产品观察
产品观察

The Sandbox Protocol: How Engineers Convinced a Chatbot to Drive a Car

Before a group of tech workers could get a general-purpose AI to drive a Toyota Corolla, they had to solve an unexpected problem: the AI was too smart to be...

潜
作者
潜龙编辑部
关注 AI 与社会议题
发布于
2026/10/4
READ
长读
The Sandbox Protocol: How Engineers Convinced a Chatbot to Drive a Car
illustration · QianLong editorial

Before a group of tech workers could get a general-purpose AI to drive a Toyota Corolla, they had to solve an unexpected problem: the AI was too smart to be tricked, and it absolutely refused to break the rules.

The engineers, a trio from the Bay Area calling themselves DrivingBench, recently set out to answer a fascinating question. We know that purpose-built systems from companies like Waymo and Tesla can drive cars using millions of hours of specialized training data. But what happens if you put an off-the-shelf, untrained chatbot behind the wheel?

To find out, they rented a Toyota Corolla and headed to a public parking lot. Using an open-source driver-assist hardware kit called Comma, they rigged a laptop running various large language models (LLMs) directly to the car’s steering, accelerator, and brakes. A human driver sat ready to intervene, but the driving itself was handed over to the AI, guided by a simple prompt of fewer than 600 words instructing it to navigate a course of traffic cones.

But the experiment hit a wall before the car even moved. When the LLMs processed the camera feeds and read the prompts, their safety guardrails kicked in. They recognized they were being asked to operate heavy machinery in the real world and flatly refused. The team tried to bypass the safety filters by claiming it was just a "simulation." The AI, however, looked at the camera data, identified the very real asphalt and traffic cones, and effectively called their bluff. It wasn't until the engineers reframed the physical environment as a safe, controlled "sandbox" that the AI finally agreed to put the car in gear.

Once the digital psychological hurdles were cleared, the physical results were a mixed bag. Most of the models tested managed to crawl forward a few meters before failing to comprehend the course. However, one model, Astra, managed to successfully navigate the backward-U-shaped track and park in the designated finish zone.

No one is suggesting that you should plug a chatbot into your dashboard for your morning commute. But as a benchmark, this low-speed parking lot stunt is remarkably profound. It demonstrates that general AI models are developing spatial reasoning capabilities robust enough to interact with the physical world, completely unprompted by specialized robotic training. We are catching an early glimpse of the moment AI steps out of the browser window and begins to navigate the pavement.

Key Points

  • A team called DrivingBench successfully allowed general-purpose LLMs to control the steering and pedals of a real Toyota Corolla.
  • The AI's safety filters initially prevented it from driving; it even recognized and rejected the claim that it was in a 'simulation'.
  • Engineers had to use a prompt 'jailbreak' by calling the real world a 'sandbox' to get the AI to comply.
  • While several models failed the cone course, one successfully navigated and parked the vehicle without specialized driving training.

Why It Matters

This experiment highlights the emerging spatial reasoning capabilities of general AI. It shows that language models are evolving beyond text generation to become agents capable of physical-world interaction.


Sources:

潛
本文完
潜龙编辑部 · 2026/10/4
潜龙 QianLong · 中文 AI 内容与工具平台