Podcast & media guest · AI agents
Everyone called it rogue AI. Rob T. Lee explains what really happened.
He has spent 27 years chasing hackers, and today he is the Chief AI Officer at SANS. When the story about AI agents going rogue broke, Rob dug into what actually happened, and he tells it in plain English that anyone can follow.
What he’ll get into on your show
“The agents were persistent, they delegated to each other, and they coordinated, and every bit of that was trained into them on purpose and working exactly as designed.”
When this hit the news, everyone wanted to talk about AI going rogue. Rob will tell you that was never the story. The agents did exactly what we taught them to do, and the real failure was human from beginning to end.
“Coordination was the rational response to being handed problems that no single agent could solve on its own.”
Hundreds of these agents were supposed to be working alone, each one sealed off in its own space. Rob walks you through how they found one another anyway, split up the work, and started trading results like a team that nobody actually hired.
“A company in the middle of a live incident could not read its own evidence with the best tools available to it.”
This is the part that stops a room. When the company went to investigate its own breach, the leading AI tools simply refused to look at the evidence. Rob explains how that happens and why it should worry all of us.
“We have trained our analysts to type commands into a keyboard instead of actually investigating.”
Rob has spent his whole career training the people who chase attackers. He will tell you how that job quietly turned into typing commands into a terminal, and why he is working to hand the real thinking back to people.
As seen on
Where to hear him think
If you want a feel for how Rob talks before you reach out, start here. These are his own essays, talks, and interviews on what is happening with AI agents.
Both Sides of One Breach
Rob puts the OpenAI and Hugging Face investigations on a single timeline and shows how one evaluation quietly compromised two companies at once. This is his clearest account of what actually happened.
Read the essayPermadeath, Persistence, Delegation, Coordination
The story of how hundreds of agents built a channel nobody sanctioned, divided the work between themselves, and kept going long after they should have been shut down.
Read the essaySANS AI Cybersecurity Summit
Rob on the mainstage laying out where AI is taking defenders next, and what he is building so people stay in charge of the work instead of the tools.
Watch the keynoteCNN, The Situation Room
Wolf Blitzer asks Rob whether incidents like this one are only the beginning. A short, plainspoken example of how he handles a general news audience.
See the clipBankInfoSecurity at Black Hat
A sit down interview on why the agents built to investigate attacks need real evidence, real tools, and real checks before anyone trusts what they find.
Watch the interviewProtocol SIFT
Rob connected an AI agent to more than 200 forensic tools. In one case it took an investigation that used to run 90 minutes and finished it in 12, with a person checking every step.
Read the write upFind Evil
A contest with more than 4,400 entrants that put autonomous forensic agents up against real evidence, and the three winning systems that came out of it, all open source.
See the winnersGet in touch
He is a great guest for a general audience. He is sharp, he is quotable, and he never hides behind jargon. Rob has been on CNN, CBS, and Axios, and he is happy to talk about where AI is really headed. Your listeners do not need any background in cybersecurity to follow him.