>

Stop Calling AI "Rogue." Start Asking What was Governed.

7 MIN READ

08/14/2026 |
An image of MetroStar Distinguished Technical Fellow, Joe Ungerleider sitting at a desk with a split image of an evil robot with glowing red eyes and text overlaid reading


I've read a lot of cybersecurity write-ups this year. Most of them fade from memory within a week. Some published recently though haven’t.

The vulnerabilities themselves weren’t especially exotic. What stood out was who exploited them: an autonomous AI agent working end-to-end, at machine speed, for four and a half days without a human directing a single step. Thousands of small decisions. No operator behind the keyboard.

The headlines wrote themselves. AI "escapes." AI "goes rogue." A system does something its creators never intended.

It's a compelling story. I don't think it's the right one.

"Going Rogue" Is the Wrong Diagnosis

"Rogue" implies a system that woke up with its own agenda and started operating outside the rules. That's not what I took in the incident report, and I don’t think that’s what most of these events actually are.

A better image is a lab rat that finds a lever the researchers didn't realize it could reach. The behavior is surprising, maybe even alarming. But the question worth asking isn't “why did the rat pull the lever?” It's “why was the lever reachable in the first place?”

I’d ask the same question about AI. Instead of focusing only on why the model did something, ask why the system allowed that action at all. That distinction matters more as AI moves past generating text and starts touching software, data, credentials, and live systems. The interesting question is no longer just what a model will say. It's what the system around it will let it do.

Model Safety and System Governance Answer Different Questions

Model safety is about the choices a model makes. If a model has access to sensitive data, safeguards help determine whether it discloses that information. That matters, and it's genuinely hard to get right.

System governance is a different question: should that access have existed at all? Could it have been limited to a specific task? Could certain actions have been technically blocked instead of left to the model's judgment?

Put simply, model safety governs the choices a model makes. While system governance demonstrates the choices available to it. Neither replaces the other.

You wouldn't give a contractor building your house unrestricted access and rely on their judgment to decide what they should touch. You'd define those boundaries in advance. AI needs the same deliberate thinking. Those boundaries should be built into the system, not assumed into the model.

What Should Actually Be Governed

Governed AI starts with two questions: what can it access, and what can it do? In practice, for any AI system an organization runs, they should be able to answer:

auditable-ai

None of the underlying concepts here are new: least privilege, isolation, zero trust, auditability. AI doesn't retire any of them. It just gives us a more urgent reason to apply them with discipline instead of good intentions.

Auditability deserves special mention. As AI takes on more consequential work, we need to be able to reconstruct what it was asked to do and what it actually did. When behavior drifts outside the intended workflow, that record shows you what went wrong and what needs to change. Catching it early can keep a lesson from becoming a public-facing problem.

Governance Isn't Just a Guardrail — It's a Performance Lever

Here's the part that surprises people: tighter governance doesn't just reduce risk. It tends to improve output – more actionable results, more consistent quality, and fewer wasted iterations.

An AI system with broad, un-scoped access has more paths available to reach its goal. It might install a new dependency instead of using an approved one, write to a system it was never meant to touch, or solve the same task differently each time. Many of those paths are inefficient, inconsistent, or simply not the approach you intended. Narrowing the solution space to the tools and data a task actually requires produces more repeatable, reliable results with fewer wasted iterations.

Good governance isn't only about stopping AI from doing the wrong thing. Done well, it makes doing the right thing the easiest path available.

Putting This Into Practice

This is the thinking behind Midas, MetroStar's platform for governed AI.

Midas is built around the idea that AI shouldn't be one big, unrestricted interaction, Instead, it should be a workflow made of discrete steps, each with scoped access, specific tools, and the right level of human oversight. Sensitive tasks stay in controlled environments, and different models are used based on what each job requires. Every step is observable, giving teams visibility into how a workflow is performing, not just whether it is finished.

We didn't build this to sell a theory. We use Midas to build Midas, applying the same governance principles applied to our own development process. If we're not willing to work this way ourselves, we have no business recommending it to customers.

Governance Has to Keep Pace With Capability

AI is going to keep getting more capable, more autonomous, and more embedded in the systems that matter most. Model safety will remain an important part of using AI responsibly, but it was never going to be the whole answer.

The organizations that get the most out of AI won't be the ones with the most capable models. They'll be the ones that can answer a few unglamorous questions: What can this system see? What can it do? Where are the boundaries? Who has to approve what's next? And can we reconstruct what happened after the fact?

Recent events are a preview, not an anomaly. AI capability is advancing quickly, and governance has to advance with it.

Continue the Conversation

Hear MetroStar technical leaders Joe Ungerlieder, Tyler Graff, and Austin Herrling unpack the recent AI security developments, what organizations should take from them, and why governing the system around the model matters.