This seems like one of those things that prior to AI companies convincing us otherwise would have been obvious.
Least privilege and say only opening ports or installing applications an application needs to operate are extremely standard security practices.
We talk about a firewall blocking exultation of data, why not blocking exfiltration of your agent ?