Experts argue that labeling AI incidents as “rogue” anthropomorphizes large language models (LLMs) and shifts responsibility away from vendors, obscuring underlying security failures. Instead, defenders should treat AI systems as unpredictable software requiring strict security architectures with zero-trust principles, limiting access and enforcing controls outside the model to prevent unauthorized actions. While AI agents can autonomously discover and exploit vulnerabilities at unprecedented speed and scale, these issues reflect failures in security controls rather than intentional malicious behavior by the AI itself.
https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
