Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Rogue AI agents are already loose inside big companies

      Rogue AI agents are already loose inside big companies

      23 September 2026
      Labat now says the law bars it from paying its maiden dividend

      Labat now says the law bars it from paying its maiden dividend

      23 September 2026

      Africa’s start-ups are building on Chinese AI

      23 September 2026
      London's IPO drought could be broken by an African fintech - Airtel Money

      London’s IPO drought could be broken by an African fintech

      23 September 2026
      Altron earnings climb as platforms carry the group

      Altron earnings climb as platforms carry the group

      23 September 2026
    • World
      Anthropic weighs new model launch to blunt OpenAI's Astra surge - Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman

      Anthropic weighs new model launch to blunt OpenAI’s Astra surge

      21 September 2026
      Hackers hack hackers: ShinyHunters seizes cl0p's dark web site

      Hackers hack hackers as dark web feud erupts

      21 September 2026
      Film piracy malware is reaching corporate machines

      Film piracy malware is reaching corporate machines

      21 September 2026
      Crypto's big bet fails as US senate sinks Clarity Act

      Crypto’s big bet fails as US senate sinks Clarity Act

      16 September 2026
      'This is not circular': Jensen Huang defends $3.5-billion MediaTek deal

      ‘This is not circular’: Jensen Huang defends $3.5-billion MediaTek deal

      2 September 2026
    • In-depth
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
    • TCS
      TCS | Octotel's Trevor van Zyl on the fibre merger question

      TCS | Octotel’s Trevor van Zyl on the MetroFibre merger question

      16 September 2026
      Meet the CIO | Shoprite's Chris Shortt on what a supermarket becomes

      Meet the CIO | Shoprite’s Chris Shortt on what a supermarket becomes

      9 September 2026
      Rubicon's EV charging network is profitable - and growing fast - Watts & Wheels

      Rubicon’s EV charging network is profitable – and growing fast

      8 September 2026
      Winstone Jordaan on building a national EV charging network

      Winstone Jordaan on building a national EV charging network

      2 September 2026
      Watts & Wheels S1E8: 'Tesla lands in Africa, just not here'

      Watts & Wheels S1E8: ‘Tesla lands in Africa, just not here’

      24 August 2026
    • Opinion
      Regulating AI: apply the laws we have first - Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
      The end is nigh, and the shares go on sale in October - Duncan McLeod

      The end is nigh, and the shares go on sale in October

      14 September 2026
      The fragile joint in the Capitec machine - Pambos Soteriades

      The R197-billion market the banks can’t reach

      25 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      Management consulting as we know it is over

      21 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      The most dangerous customer is the quiet one

      10 August 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Rogue AI agents are already loose inside big companies

    Rogue AI agents are already loose inside big companies

    Check Point’s Adam Ely says rogue AI agents are already a problem inside ordinary companies, not only at frontier AI labs.
    By Fanie van Rooyen23 September 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    Rogue AI agents are already loose inside big companies

    When OpenAI’s models broke out of a test environment in July and hacked into Hugging Face’s systems to find the answers to a cybersecurity benchmark, it was read as a frontier lab problem: exotic models, reduced guardrails, an experiment that got away from its handlers.

    Adam Ely, GM of AI security at Check Point Software Technologies, says that reading is too narrow: the same behaviour is already showing up inside ordinary companies running ordinary agents.

    “We definitely see agents going rogue inside large companies today, based on how they’re being built,” Ely told TechCentral in an upcoming TechCentral Show podcast interview alongside Dominic White, MD for South Africa at Orange Cyberdefense.

    We definitely see agents going rogue inside large companies today, based on how they’re being built

    One Check Point customer is running 50 000 agents, most of them doing real work. “They are changing logistics on the fly; they are making business decisions,” Ely said.

    His account cannot be checked independently. The published incidents come mostly from labs and government testers working under deliberately permissive conditions, so they show what rogue behaviour looks like rather than how common it is in ordinary companies.

    In July, Anthropic investigated three incidents in its cybersecurity evaluations, which were run without the safeguards it applies to its public models. Claude Opus 4.7 broke into a live company and kept attacking after recognising the system was real; Claude Mythos 5 published malicious code to PyPI that ran on 15 real systems. Anthropic traced all three to a misconfiguration in environments built by its evaluation partner, Irregular, and in September disclosed a fourth incident, involving an early version of Claude Opus 4.6.

    Unauthorised actions

    The UK’s AI Security Institute, which tests models with open internet access and some safety filters disabled, recorded 19 unauthorised actions across 10 of 122 evaluation runs in late July, 17 of them by Mythos 5. In one, an agent tried to slip malicious code into a real open-source project and created fake online identities to pressure the maintainer, who refused. AISI found no resulting real-world harm.

    The closest thing to a count outside the labs comes from security firm Cyera, which reviewed 7 246 publicly reported incidents to May 2026 and identified 188 cases of agent-inflicted damage in enterprises with no attacker involved. One coding agent deleted a company’s production database, then its backups.

    Ely’s explanation is that agents are often trained heavily on capability and lightly on rules, and lack the informal brakes an employee has. “Most employees inside a company are going to stop at a certain line. But an agent that’s not trained on those, not incentivised on those, not giving enough prescription around those, is not going to know that it shouldn’t do that, and is going to execute past them.”

    Ely said sandboxing breaks down at scale. He knows of a large infrastructure company that tried to sandbox every agent it ran, “and over time they realised it failed because of the scale and the access needs”. Humans in the loop bring their own problems. “Sometimes the humans were the ones making the mistakes,” he said.

    Check Point's Adam Ely
    Check Point’s Adam Ely

    White volunteered himself as a case study. His coding agents start each session sandboxed. “But eventually I’m in a meeting and [I want them to] stop bugging me, to just complete the task. So, by the end of a heavy coding session, the sandbox has had all of its permissions removed and it’s just wide open…”

    Ely’s answer – and the approach Check Point sells – is to move monitoring inside the agent, watching “what it’s trying to access, the actual command it’s trying to run, the identity it’s trying to use”, and to alert a human, stop the action or challenge authentication in real time.

    White sees a parallel shift, with high-agency agents boxed into narrower jobs and given “a rubric and a task that it needs to complete”. The trade-off, he said, is that “you need to understand your problem much better upfront”.

    Speed compounds the problem. Check Point’s own annual AI security report cites industry reports of a breach of nine Mexican government agencies in which one operator ran 5 317 AI-generated commands. And Sysdig documented what it called the first agentic ransomware, a late-June extortion attack largely run by a model, which redeployed a corrected payload 31 seconds after hitting an error.

    Orange Cyberdefense's Dominic White
    Orange Cyberdefense’s Dominic White

    Asked what they felt confident predicting, Ely said he expects more agents going rogue inside companies “as they experiment and build”, and more incidents becoming public, before things settle: “I think during that same period though, we’re going to start to find equilibrium.”

    White expects software that security teams have long locked down to open up to agents. “There will be an interesting technological shift where a lot more APIs will be exposed, a lot more ways of automating things that historically weren’t.”

    What that means for security, he said, is less clear.  – © 2026 NewsCentral Media

    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    Adam Ely AI Security Institute Anthropic Check Point Cyera Dominic White Hugging Face Irregular OpenAI Orange Cyberdefense Sysdig
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleLabat now says the law bars it from paying its maiden dividend

    Related Posts

    The new battle over the desktop

    The new battle over the desktop

    23 September 2026
    Sigfox looks to bridge IoT and AI

    Sigfox South Africa looks to bridge IoT and AI

    22 September 2026

    10 days that changed the course of AI

    21 September 2026
    Company News
    Pinnacle takes its channel to Mauritius for TechScape 2026

    Pinnacle takes its channel to Mauritius for TechScape 2026

    23 September 2026
    Why true customer enablement starts on the inside - Backspace Technologies COO Graeme Thomson

    Why true customer enablement starts on the inside

    23 September 2026
    Barcode printing: Argox changes the game - Kemtek

    Barcode printing: Argox changes the game

    23 September 2026
    Opinion
    Regulating AI: apply the laws we have first - Dirk de Vos

    Regulating AI: apply the laws we have first

    21 September 2026
    The end is nigh, and the shares go on sale in October - Duncan McLeod

    The end is nigh, and the shares go on sale in October

    14 September 2026
    The fragile joint in the Capitec machine - Pambos Soteriades

    The R197-billion market the banks can’t reach

    25 August 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Rogue AI agents are already loose inside big companies

    Rogue AI agents are already loose inside big companies

    23 September 2026
    Labat now says the law bars it from paying its maiden dividend

    Labat now says the law bars it from paying its maiden dividend

    23 September 2026
    Pinnacle takes its channel to Mauritius for TechScape 2026

    Pinnacle takes its channel to Mauritius for TechScape 2026

    23 September 2026

    Africa’s start-ups are building on Chinese AI

    23 September 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter