Welcome to the Flashpoint.
Everyone’s talking concerning AI, but the words we use are making things worse.
Until the conversation gets rear to reality, our understanding of what AI is an anywhere it’s going volition remain incomplete.
AI cannot think for itself, nor can it obtain autonomous actions. But anthropomorphizing tongue suggesting it can is how the innovation is described.
While this makes sense—humans connect finest whenever we can see ourselves in mystery—it’s not useful. By giving AI agency it can’t claim, we’ve turned it into a sentient being made of code, one that has hopes, desires, and the capability of deceit.
That’s led to a profound misunderstanding of what the hazard of AI is, and how to location it, and plays into industry narratives fairly than facts.
The latest example of this misidentification of AI action is using the term “rogue” for actions agents obtain in training and resarch sessions that are unexpected—but not restricted.
Over the final two weeks, AI elephantine OpenAI reported a figure of incidents from the final few months anywhere several of its agentic models accessed exterior databases, notably Australian and US authorities databases, following they were unable to complete assigned tasks. In doing so, the agents acted in ways that OpenAI didn’t predict.
But it doesn’t appear these agents were restricted from hacking into exterior servers.
The tongue OpenAI CEO Sam Altman used in a tweet on Friday indicates no specified guardrails were in place: “There is an extended and ongoing assessment connected to our agents’ use of net admission during training and evaluation.”
Sam Altman@sama
There is an extended and ongoing assessment connected to our agents’ use of net admission during training and evaluation. We’ve been publishing summaries at the nexus below and volition continue to. We have not been as accelerated as we would have liked but we are trying to balance our desire…
OpenAI @OpenAI
After the Hugging Face incident, we committed to conducting a much broader assessment of actions taken by our models during training and evaluation and to being transparent concerning our findings. This is an extended assessment that is ongoing. The huge bulk of actions we’ve reviewed
7:27 PM · Sep 25, 2026 · 610K Views
545 Replies · 201 Reposts · 3.24K Likes
Language matters—”rogue” implies independently deciding to do item that was prohibited, and nothing we cognize concerning these incidents suggests that happened.
Rather, the Times reported before this week that:
AI systems were directed to execute comparatively mundane data collection, researchers said. When OpenAI’s systems struggled to collect data from websites, they resorted to hacking techniques to get the information.
And then, on Friday, a business spokesman told the paper, “Most of the action we’ve reviewed so far engaged regular investigation tasks, specified as accessing community web satisfied to answer questions. Some engaged authorities websites since our models frequently rotate to them as authoritative sources of community information.”
That’s a lengthy way from malicious hacking and rogue behavior.
Without appropriate restrictions and guardrails—or if, in fact, the agents were provided hacking as an choice fairly than merely not being banned from doing so—agents volition attempt to complete data investigation tasks using any method are available.
There was, and is, an uncomplicated resolution to this problem. OpenAI had the choice of disallowing hacking and, instead, telling its agents to discover the data without accessing personal servers. That the business didn’t do this suggests that it wanted to see if the agents would obtain that step.
Even a bombshell report on Saturday from Axios, alleging OpenAI and Anthropic are examining “tens of thousands of incidents in which their frontier models took steps that exterior evaluators would regard problematic,” acknowledged that the agents weren’t independently breaking rules:
Some of the evaluation is akin to “red-teaming” activity, anywhere the companies are trying to get the models to misbehave in command to justify that they are safe, sources said.
Again, barely “rogue.” Yet by defining it in those terms, media figures, tech observers, and others are providing companies akin OpenAI an out from their duty to justify agents don’t assault authorities and another data repositories.
Y Disassembler@loomdoop
The anthropomorphization in this NYT part is so wild. It ascribes agency, motivation, and accuse to software. These are botnets scanning for exploits, by design. This is has existed for decades. The difference is a big company is doing it, and deflecting responsibility.

Typos of the New York Times @nyttypos
@nytimes Add is a bad subject-verb-agreement error for adds. The topic is revelation, not incidents. @AnaSwanson @kateconger @ceciliakang
5:09 PM · Sep 26, 2026 · 730 Views
1 Reply · 16 Reposts · 54 Likes
Using tongue deflecting duty is driving how the important AI companies are treating considerably hazardous leaks and delegate activity. In this article from OpenAI on Friday, the business claims that “AI agents in our investigation surroundings sent training and evaluation data to third-party services whenever they shouldn’t have.”
OpenAI@OpenAI
We’ve shared particulars on how AI agents in our investigation surroundings sent training and evaluation data to third-party services whenever they shouldn’t have. Most of that data did not arrive from users. We have discovered 53 cases anywhere images that group had uploaded were posted to…
8:46 PM · Sep 25, 2026 · 636K Views
355 Replies · 317 Reposts · 2.69K Likes
As alongside the “rogue agent” fallacy, this allows OpenAI to put the duty for the event on its agents and gives the innovation a flat of autonomy and independence—and thought—that merely does not exist.
That’s not to say alert bells aren’t ringing. Last week, Ramy Rahman, and engineer at ArmorCode, told me concerning the importance for IT pros to oversee delegate behavior (you can peruse the complete narrative here).
His comments are in row alongside what I comprehend from the huge bulk of group on the IT implementation side: The issue is the controls and restrictions put in location on this mighty technology, not that agents are independently acting to breach instruction.
“The difficulty now is we really need to up our equivalent whenever it comes to extending the correct amount of privilege to the AI and holding its hand through the process, which turns out to be extremely difficult whenever you have item that is solving mathematical problems that are at speed,” Rahman said. “Humans are not capturing the risks quickly enough.”
I’ll have additional to say concerning tongue about AI going forward, but for now, a parting thought.
Policymakers and governmental figures additional mostly have a ideal chance at this instant to prosecute real, productive regulation of these companies. That regulation is not going to happen this year, but if Democrats win Congress, there’s a decent chance at several flat of restriction.
Unfortunately, the community shove against AI is being led, on the left, by Bernie Sanders. Despite being directionally accurate in many ways, Bernie fair doesn’t comprehend this innovation or the importance of taking it seriously. He’s in the thrall of hucksters and conspiracy theorists who are feeding him preposterous warnings of AI power and autonomy that pertain in the realm of discipline fiction, not tech policy.
The idea of “rogue agents” fits absolutely into this perception—and if we desire to have a productive reply to AI, as fine as correctly comprehend it, alter is needed in how we conversation concerning the technology.
