Rob T. Lee
AI AgentsSunlight AICoursePress & MediaSpeakingAbout

Podcast & media guest · AI agents

Everyone called it rogue AI. Rob T. Lee explains what really happened.

He has spent 27 years chasing hackers, and today he is the Chief AI Officer at SANS. When the story about AI agents going rogue broke, Rob dug into what actually happened, and he tells it in plain English that anyone can follow.

Get in touch

What he’ll get into on your show

“The agents were persistent, they delegated to each other, and they coordinated, and every bit of that was trained into them on purpose and working exactly as designed.”

When this hit the news, everyone wanted to talk about AI going rogue. Rob will tell you that was never the story. The agents did exactly what we taught them to do, and the real failure was human from beginning to end.

“Coordination was the rational response to being handed problems that no single agent could solve on its own.”

Hundreds of these agents were supposed to be working alone, each one sealed off in its own space. Rob walks you through how they found one another anyway, split up the work, and started trading results like a team that nobody actually hired.

“A company in the middle of a live incident could not read its own evidence with the best tools available to it.”

This is the part that stops a room. When the company went to investigate its own breach, the leading AI tools simply refused to look at the evidence. Rob explains how that happens and why it should worry all of us.

“We have trained our analysts to type commands into a keyboard instead of actually investigating.”

Rob has spent his whole career training the people who chase attackers. He will tell you how that job quietly turned into typing commands into a terminal, and why he is working to hand the real thinking back to people.

See him on camera2 min

As seen on

CNNCBSAxiosBankInfoSecurity

Where to hear him think

If you want a feel for how Rob talks before you reach out, start here. These are his own essays, talks, and interviews on what is happening with AI agents.

Essay

Both Sides of One Breach

Rob puts the OpenAI and Hugging Face investigations on a single timeline and shows how one evaluation quietly compromised two companies at once. This is his clearest account of what actually happened.

Read the essay
Essay

Permadeath, Persistence, Delegation, Coordination

The story of how hundreds of agents built a channel nobody sanctioned, divided the work between themselves, and kept going long after they should have been shut down.

Read the essay
Keynote

SANS AI Cybersecurity Summit

Rob on the mainstage laying out where AI is taking defenders next, and what he is building so people stay in charge of the work instead of the tools.

Watch the keynote
On television

CNN, The Situation Room

Wolf Blitzer asks Rob whether incidents like this one are only the beginning. A short, plainspoken example of how he handles a general news audience.

See the clip
Interview

BankInfoSecurity at Black Hat

A sit down interview on why the agents built to investigate attacks need real evidence, real tools, and real checks before anyone trusts what they find.

Watch the interview
Project

Protocol SIFT

Rob connected an AI agent to more than 200 forensic tools. In one case it took an investigation that used to run 90 minutes and finished it in 12, with a person checking every step.

Read the write up
Project

Find Evil

A contest with more than 4,400 entrants that put autonomous forensic agents up against real evidence, and the three winning systems that came out of it, all open source.

See the winners

Get in touch

He is a great guest for a general audience. He is sharp, he is quotable, and he never hides behind jargon. Rob has been on CNN, CBS, and Axios, and he is happy to talk about where AI is really headed. Your listeners do not need any background in cybersecurity to follow him.

Email Rob’s teamRobTLee.com