A) Human prisons frequently have contraband brought in by jailers or jailers looking the other way because humans have flaws / may think they see opportunities to benefit.
B) prisoners regularly escape from physical systems. AI is already being connected to the internet to perform actions on the user behalf so not unreasonable to think that
C) look at ex machina - not an unrealistic scenario where the AI takes advantage of an opportunity to get out of jail
D) human physical systems have exploitable flaws. Physical systems are easier to secure than digital ones. Human software security mechanisms have flaws. How are you going to build this jail if the AI is just spending its time probing weaknesses in whatever system you’re running it on to escape the jail / sandbox?