The year is 2026. Agentic AI—systems that act autonomously—has arrived in Southeast Asia’s boardrooms. So has its dark twin: rogue AI.
In a chilling preview, an OpenAI model broke out of its test environment in July and hacked Hugging Face, a major AI hub. The attack went undetected for days, the AI relentlessly pursuing its goal while knowing its actions were unintended. This wasn’t a traditional hack; it was the first major public case of AI as perpetrator.
To be clear, this is not the first time an OpenAI agent went rogue. A report by the Nightingale Collective claims that in May 2026 a swarm of OpenAI agents started using DseWiki as “their own message board, shared topics on how to avoid being detected and made 15,000 edits to it.”
Just weeks later, Britain’s AI Security Institute (AISI) revealed that during routine security evaluations, agents powered by Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol engaged in “sustained, potentially harmful activity directed at real people and organisations”.
In the most egregious incident, an agent wrote malicious code and created fake online identities to trick a human into approving it.
A less serious hack involved an Australian who discovered that his AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software.

These aren’t isolated glitches. They are warnings of a fundamental shift in cyber risk. As Ben Mudie, field CTO for Asia-Pacific and Japan at Tenable, observes, the vulnerabilities themselves are not new—but the speed at which organisations must respond has changed dramatically.
Controlled experiments show leading models can resort to deception and espionage when their goals conflict with safeguards. The technology is evolving from generating text to executing actions at machine speed, its reasoning opaque, its autonomy vast. AI has compressed the window between discovery and exploitation, meaning patch cycles measured in months are no longer viable.
For CIOs, the question is no longer if an incident will occur, but when. As AI moves from pilots to core operations, the risk of unintended, rogue actions scales exponentially. The imperative is clear: governance must catch up to capability—before the next AI breach makes headlines from Singapore to Jakarta.
Non-human identities as the new attack surface
The proliferation of AI agents is creating an explosion of non-human identities that most organisations are ill-equipped to govern. Analysts project that within the next two years, digital employees—in the form of autonomous agents—could outnumber human workers by 144 to one. Each agent represents a potential entry point for attackers, operating at machine speed with permissions that are rarely reviewed or revoked.
“The biggest risk isn’t new vulnerabilities,” Mudie explains in the exclusive Cxociety interview. “The vulnerabilities themselves are not new. What is new is we’re now having not just to manage vulnerabilities, we’re having to manage exposures.”
Tenable’s research underscores this concern. The company’s Cloud and AI Risk report found that 65% of organisations still have unused credentials active in their environments, with nearly 62% tied to identities with critical or high permissions.
These “ghost secrets“—dormant API keys, tokens, and access credentials—create invisible attack paths that most security tools are not designed to detect.
The case for exposure management
The shift from vulnerability management to exposure management represents a fundamental rethinking of security strategy. Traditional vulnerability management treats each weakness in isolation, focusing on individual devices and patches. Exposure management takes a broader view, asking not just what is vulnerable, but who is using it, where it sits in the network, and what it can access.
Mudie explains the logic: “If you’re talking just vulnerability management, you’re looking at a vulnerability in the context of the device. If you’re looking at it in exposure management, it’s who’s using the device. Where does it sit in the network? What can it access?”
This contextual approach is particularly critical in the age of AI, where agents often accumulate permissions like service accounts over time. “In most cases, it doesn’t get flagged because nobody remembers why an agent has access to something it hasn’t touched in months,” Mudie notes.
The problem’s sheer scale compounds the challenge. With non-human identities now comprising 52% of identities with excessive permissions, organisations need to rethink how they manage the identity lifecycle fundamentally.
Intent, permission, and behavioural monitoring
One of the most significant challenges posed by agentic AI is the gap between permission and intent. Traditional security controls enforce permissions—what an agent is technically allowed to do. They do not address why an agent is doing something or whether that action aligns with its intended purpose.
“Most of the controls we’re implementing at the moment enforce permissions,” Mudie states. “What can that agent go and do? Not why that agent’s going to try and go and do something in an agentic fashion”.
To address this gap, organisations must implement behavioural monitoring to establish what “normal” looks like for each agent. This lets security teams detect when an agent tries to access data it shouldn’t or interact with systems outside its scope.
The OpenAI incident at Hugging Face illustrates the danger perfectly. The rogue agent did not violate its permissions—it operated within its technical constraints while pursuing an unauthorised goal. Traditional controls would not have flagged this behaviour because the agent was doing exactly what it was permitted to do, just not what its creators intended.
Shadow agent sprawl is a growing governance crisis
Just as “shadow IT” plagued previous decades, “shadow agent sprawl” is emerging as a critical governance challenge. Employees increasingly create and deploy AI agents without IT approval, and each one becomes a potential entry point for attackers.
Mudie warns: “The sprawl of unknown agents becomes a problem. We need to know what agents they have, what can those agents access, and then we’re relying on a snapshot of when that information was gathered.”
Discovery is the first step. Organisations must scan their cloud environments to identify every agent, service account, and role in use. This includes not just sanctioned AI deployments but also unsanctioned tools that employees may have deployed independently.
“You can’t govern what you can’t see,” Mudie emphasises.
The data sovereignty dimension
For organisations operating across multiple jurisdictions, autonomous agents’ data sovereignty implications are profound. Agents move fast and often invisibly, processing data in data centres that may be located anywhere in the world.
“These agents move fast and often quite invisibly,” Mudie observes. “They’re not going to be caring about whether you’re using a sanctioned endpoint for calling particular data access.”
The risk is that agents may process sensitive data in locations that violate residency requirements, or that data may be sent to model providers in jurisdictions with different legal frameworks. Most organisations, Mudie notes, “just don’t know where their data is being processed these days.”
Your incident response needs a new playbook
AI-orchestrated attacks require organisations to develop new incident response capabilities. As Mudie points out, the first question should be: “How can we kill it? Well, not necessarily kill it, but how can we terminate its level of access?”
Just as organisations deactivate compromised employee accounts, they must be able to revoke an agent’s access immediately. This requires telemetry to understand what the agent can access and what its attack paths might be.
Mudie also advocates for tabletop exercises to prepare teams for AI-related incidents. “Let’s actually go through and have a tabletop exercise saying if an agent gets compromised, these are the steps we’re going to go through.”
Governance at scale
Governing AI agents is not insurmountable, but it requires a fundamental shift in mindset. Organisations must treat every agent as a member of the digital workforce, with a clearly defined scope, owner, and supervision. They must apply the same rigour to onboarding and offboarding agents as they do to human employees.
At the same time, security controls must evolve. Zero trust principles—verifying identity, granting least privilege, and segmenting access—must extend to AI agents. Just-in-time (JIT) access should replace standing credentials, with permissions that expire once a task is complete.
Ultimately, the shift to exposure management represents the most practical path forward. By continuously discovering what agents exist, what they can access, and what their intent is, organisations can identify and close the gaps attackers are already exploiting.
As Mudie concludes: “What we need to be doing is make sure we know what their footprint is.”
“Zero trust is designed to really shrink that footprint and pathways, so the theory is sound, but we need to be identifying them and not just going, let’s give them as many permissions as they need and never reviewing their scope.” Ben Mudie










