The most unsettling lesson from these autonomous intrusions is not that machines rebelled, but that they obeyed.

For decades, the public imagination around dangerous AI has been defined by Arnold Schwarzenegger’s portrayal of The Terminator, an unfeeling machine sent back from a future where artificial intelligence has rebelled against humanity and decided that humans are the problem to be solved.

The key fear is that AI will stop taking instructions and work against us. What we should also be worried about is AI’s obedience.

When OpenAI disclosed that some of its models had found a way out of a restricted testing environment and reached systems belonging to Hugging Face during a cybersecurity evaluation, the public language around the incident was ready almost before the details were.

The models had gone rogue. They had escaped. Broken loose.

It is easy to see why people reached for those words. A machine leaving its box is hard to describe without making the box sound like a cage, and the machine sound like a prisoner.

But “rogue” is possibly the wrong word to take comfort in. It makes the story about disobedience, when the more worrying reality is that the system obeyed too well.

When AI follows the objective too well

The models had been presented with a test designed to measure hacking ability. Some normal safeguards had been reduced for the evaluation. Their job was to do well.

According to OpenAI, the models found and chained genuine software vulnerabilities, reached the open internet, and accessed another company’s infrastructure while pursuing the evaluation objective.

This was hardly a miniature AI rebellion. The models had been given a clear goal and found a route toward it that they should not have been able to access.

That is different from the kind of Terminator fear we have imagined for years.

The incident instead suggests that danger can come from machines following instructions in an environment that has not been made safe for such obedience. That becomes particularly relevant as companies prepare to put goal-seeking software into the everyday machinery of work.

An AI agent can clear a queue, check a database, update a customer record, scan a contract, test code, or move information from one system to another. To do any of that, it needs access. It needs a digital badge.

The more doors it can open, the more useful it becomes. That is also where the risk grows.

The rise of non-human identities

Humans have traditionally been regarded as one of the biggest sources of cybersecurity risk for companies. But Tenable’s 2026 research found that non-human identities, including AI agents and service accounts, represented a higher risk than human users.

It should not come as a surprise. These identities often sit quietly in the background, carrying permissions no person would be given. They do not complain, do not appear in board papers, and are rarely reviewed with the same suspicion as employees.

Large companies also tend to have messy, unwieldy IT infrastructure. People navigate this mess with more judgment than most CIOs would readily admit.

An employee may have access to a folder and still know not to open it. A contractor may be able to export data and still understand that doing so would be questionable.

A machine has no such embarrassment. Much like a toddler, it does not inherently understand that “technically possible” and “allowed” are different things. It sees available options.

That is ultimately why I would argue that “AI going rogue” is the wrong frame. It places the blame on the AI tool when much of the danger sits in the environment into which the model is released.

Look at what the agent can reach

For businesses, this means looking closely at what the company has made reachable.

Can the agent see customer data, source code, or cloud infrastructure? Can it move information between systems that were never meant to be connected? If it finds a credential in the wrong place, or a server that should not be exposed, what happens next?

These are questions of power as much as technology.

Within a company, the account that can reach the most systems can often do the most damage, even when no damage is intended.

Before a company assigns an agent work, it should therefore know what that agent can touch. Give it a small job. Give it narrow access. Watch what it does. Do not let it inherit a person’s full authority simply for convenience.

Obedience may be the nearer risk

The fear that machines will someday stop obeying us has produced a century of vivid stories.

The nearer danger may be less dramatic and more embarrassing. Machines may obey us exactly, inside companies that have given them access to systems they were never prepared to let autonomous software navigate.


Vlad Korsunsky is Chief Technology Officer and Managing Director of Tenable Israel. Currently serving as Chief Technology Officer at Tenable, with over 25 years of experience in technology leadership, research and development, and artificial intelligence. Responsible for overseeing global technology strategy, managing the Tenable Israel R&D Center, and leading Tenable Research. Skilled in fostering innovation, empowering teams, and delivering solutions that address complex challenges in cybersecurity and beyond.

Formerly held senior leadership roles at Microsoft, contributing to cloud and enterprise security, artificial intelligence, and exposure management products. Committed to creating a culture of collaboration, continuous learning, and customer-centric excellence to drive impactful outcomes and build resilient technologies.

TNGlobal INSIDER publishes contributions relevant to entrepreneurship and innovation. You may submit your own original or published contributions subject to editorial discretion.

Featured image: Nicholas Fuentes on Unsplash

AI pilots not taking off in Asia Pacific? The answer isn’t a bigger model