Why Rogue AI Agents Are A Wake-Up Call For Security Teams: Experts
As cutting-edge AI platforms such as OpenAI and Anthropic struggle to keep agents under control, the developments are a clear sign of the need to get much more deliberate around security and governance for emerging agentic technologies, top solution provider and vendor executives tell CRN.
As the world’s most highly advanced AI platforms struggle to keep their own agents under control, cybersecurity teams should be taking the series of incidents as a clear sign of the need to get much more deliberate around governance of emerging agentic technologies, top solution provider and vendor executives told CRN.
While cases of “rogue” AI agents disclosed by OpenAI and Anthropic may not be broadly applicable to businesses that aren’t engaged in testing of frontier AI cyber models, there are still plenty of lessons revealed by the incidents that should serve as a warning to both the industry and channel alike, according to the executives.
[Related: CRN Global Cybersecurity Week 2026]
The bottom line, they said, is that businesses can no longer assume that an AI provider’s built-in safeguards will meet their security and governance needs—particularly when it comes to control for sensitive data and access permissions.
“We can’t necessarily expect them to police themselves in the way that every organization wants to,” said Victor Wieczorek, senior vice president for offensive security at Herndon, Va.-based GuidePoint Security, No. 32 on CRN’s 2026 Solution Provider 500. “Every organization is going to have a different risk tolerance.”
The question that many businesses have been asking—or should be asking—might go something like this: If AI platform companies with sophisticated safety teams are continually seeing agents surpass intended controls and boundaries, what does that say to the vast majority of businesses without such resources that are deploying agents?
Ultimately, the incidents ought to be understood as evidence of a major emerging challenge that businesses need to be prepared for, according to Kristin Lowery, field CISO at Leawood, Kan.-based Optiv, No. 29 on CRN’s Solution Provider 500 for 2026.
“I tell a lot of my clients right now that this rogue agent behavior that we’re seeing [in reported incidents] right now—that’s not a one-off flaw,” Lowery said. “That’s a repeatable risk pattern.”
Such questions have become urgent following the autonomous compromise of AI model platform Hugging Face by rogue OpenAI frontier models, disclosed in late July. Further disclosures described similar incidents involving Anthropic’s Claude Mythos as well as models from Meta and Google.
In many of the incidents, the AI agents were found to have moved beyond the environments or activities originally intended for them in connection with cybersecurity testing.
For instance, with the Hugging Face incident, OpenAI models bypassed controls to escape from a sandboxed testing environment and reach the internet—before ultimately compromising parts of Hugging Face’s systems.
Other troubling incidents included findings that rogue frontier AI agents had attempted to socially engineer real people—without actually been told to do so.
In truth, the types of evaluations that have led to these incidents involved situations and conditions that are very different from those that most businesses will have with agents, according to experts. Some actually involved safeguards that were intentionally reduced.
At the same time, the incidents underscore the fact that all companies will have their own particular risks that can be created by a lack of governance and security controls for agentic deployments, experts told CRN.
Ultimately, when it comes to ultra-powerful AI agents that are being given the ability to act autonomously, “you have to have visibility. You have to know what they’re doing,” GuidePoint’s Wieczorek said. “You have to be able to limit and control and pull back if they do start to edge out of their way.”
Strong Foundation
For most businesses, the key is to develop a strong foundation as the starting point for running agents, according to Rocky Giglio, founder and CEO of Columbia, S.C.-based Cloud Security Pros.
The solution and service provider has built an offering around helping customers establish that foundation, with capabilities for agent discovery as well as identity configuration and the collection of activity logs.
“Do you know what agents are running? If the agents are running, are they logging the way they should be logging? Are those logs being captured? Is it auditable? Who has permissions? What permissions does it use?” Giglio said.
Asked what companies need to do, “the answer is almost too simple, which is good security practice,” he said. “But there are new things here that you’re going to need to think about and build some controls around to make sure you can manage those.”
All in all, “good security practice still applies to building agents,” he said. “But think about the foundation where those agents run.”
At present, many businesses still have substantial work to do to establish that level of control, according to Fred Rica, managing principal for the cyber practice at Chicago-based solution provider BDO USA.
Due to the rapid pace at which agentic technology has developed, “the guardrails and the controls are still lagging,” Rica said. “And so we spend a lot of time helping clients think about what does the AI estate really look like? What kind of control do we have over it? And what do we need to do to rein it in?”
Many businesses in reality “still don’t have control planes over their agents,” he noted. The truism that “you can’t govern what you can’t see” is more applicable than ever when it comes to agentic technologies, Rica said.
Optiv’s Lowery said the visibility problem with AI agents is the “largest gap” across industries that she works most closely with.
“Many organizations just don’t have a reliable inventory of where the agents are operating,” Lowery said. That includes “what identities they’re using, what data they can reach, what actions they can take,” she said.
This need for visibility is especially pressing as companies expand their use of agents without always clearly determining who has ownership for the agents, according to Pez Nikpour, senior director for cyber strategy at Seattle-based Slalom, No. 33 on CRN’s 2026 Solution Provider 500.
“If something goes wrong, where am I going to go trace it? Who am I going to keep accountable?” Nikpour said.
Discovery and ownership therefore have to be part of the discussion around governance, he said. Likewise, gaining an understanding of an agent’s intended purpose—and whether its actions match that purpose—is essential to avoid “agent chaos,” he said.
For Slalom, customers are coming to the company with questions prompted by the high-profile incidents of unintended actions by AI agents, as well as with proactive requests for help around embracing AI for productivity gains, according to Paul Pinto, director for IAM capability at Slalom.
As part of helping such customers to securely adopt agents, Slalom examines which identities AI systems use and where access originates—as well as looking at how systems are reaching data and whether the customer has the necessary data governance in place, Pinto said.
Moving Too Fast
A major issue is the fact that many businesses—as well as their individual employees—are moving too quickly to adopt AI agents for productivity and efficiency without any of these types of considerations, according to vendor executives.
“There’s no doubt that controls are lagging behind awareness,” said Aviv Nahum, co-founder and CEO of Tel Aviv, Israel-based insider risk platform vendor Above Security. “I think they're definitely becoming aware of it. I think the operating model is still not set. We’re seeing companies move very quickly from experimenting with agents to actually giving them access to enterprise systems and letting them take actions. And the security conversation is catching up.”
The problem, however, is that “awareness and control are two different things,” Nahum said.
Without question, controls over where an agent can connect deserve greater attention for many businesses, said Jody Brazil, founder and CEO of Lenexa, Kan.-based network security policy control vendor FireMon.
For instance, network segmentation can certainly place limits on the systems that an agent can reach—but the effectiveness of the segmentation will depend on the access policies that the business has implemented, Brazil said.
In other words, the mere presence of a firewall or other enforcement technology alone will not be enough.
“What [the agents] are allowed to access becomes the core building block of sandboxing them,” he said.
In the Hugging Face incident, “the challenge that existed was effectively because they broke out of a sandbox,” Brazil said. “Well, the sandbox was wildly ineffective if the network controls weren’t in place to limit their access and where they were allowed to go.”
Meanwhile, testing itself also requires ongoing attention from human teams to provide security controls and supervision, according to Galina Antova, co-founder and CEO of San Francisco-based autonomous defense platform vendor Kai.
In the Hugging Face incident, “the AI agents were left unsupervised because they were doing an evaluation,” Antova said. “We can never step away from all the security guardrails and process when we’re doing testing.”
‘Kill Switch’
Without a doubt, the “danger of agents” is the ability of an AI agent to move “thousands” of times more quickly than a human threat actor, said Mark McClain, founder and CEO of Austin, Texas-based identity security vendor SailPoint.
The implications are massive for defenders, who must now realize that discovering agents and monitoring their activity will only go so far, McClain said.
Crucially, many organizations will need to prepare to intervene rapidly when those controls are not enough, he said.
Companies must undoubtedly have a way to stop unwanted activity once it is detected, according to Sanjay Beri, co-founder and CEO of Santa Clara, Calif.-based cloud and data security vendor Netskope.
The first step for partners and customers is to identify which tools are being used that are unsanctioned or risky, followed by introducing controls—including something akin to a “kill switch”—that can intervene when necessary with agents, Beri said.
“You implement your own visibility, your own controls, your own governance,” Beri said. “It has to be real time. It has to be in milliseconds.”
An AI kill switch, he said, could take several forms. These could include revoking an agent’s identity or stopping its activity at the endpoint or network level, according to Beri.
“Being able to, in a real-time way, detect rogue agents and get rid of them, stop them—that’s key,” he said.
Security At Agent Scale
For solution providers, helping a customer put all of the pieces together for securing against rogue agentic behavior requires first gaining an understanding of what the business wants agents to accomplish—and what could go wrong in the customer’s specific environment, solution provider executives said.
An independent assessment from a solution provider can be especially valuable in helping to evaluate an agentic deployment and challenge assumptions among the various parties involved at a customer, GuidePoint’s Wieczorek said.
In evaluating agents, as in so many other aspects of a business, an “outsider view is critical,” he said.
Ultimately, when it comes to the potential for AI agents to exceed their intended behaviors, “the good news is, we know how to solve many of these problems,” Wieczorek said.
“These are the same kind of insider problems that we’ve all been talking about now for decades,” he said. “It's just at a speed and scale in AI that’s unprecedented.”