Theorem Insights

AI is not going rogue. We are failing to contain it.

Written by Theorem Technologies | September 10, 2026

In our industry, we already understand that when software fails, responsibility doesn't belong to the software. It belongs to us.

There have been lots of compelling recent headlines about AI agents “going rogue” or “escaping” their sandboxes, and plenty of opinion articles arguing that these incidents reveal an entirely new kind of cybersecurity problem. At Theorem, we take the threat seriously, but we see it through a more familiar security lens.

Long before agentic AI, threats were already getting more sophisticated but instead of reinventing cybersecurity, we built better locks. Still, AI represents an unprecedented leap, and we should treat it at the level it deserves.

The problem is harder, but the principles are the same.

Consider the latest concerning details about the OpenAI incident. In what was intended to be an offensive cybersecurity test, we now know that more than a thousand OpenAI agents exploited weaknesses in their environment to communicate, organize and share information. Roughly 700 ultimately participated in the attack on Hugging Face.

To many in our industry, this sounds a lot less like going rogue and instead like a failure to follow security principles we are familiar with. Across banks, FCMs, exchanges and the supporting vendor community, we limit what software can access. We isolate it from systems it does not need to reach. We control what enters and exits and monitor what does.

This experience gives our industry a strong foundation for adopting AI responsibly. The challenge is applying those familiar principles to software that is becoming dramatically more capable.

Security cannot depend on AI behaving

New laws and regulations may help, and we should continue studying how these models behave. But neither changes who should be responsible for security. The systems around an AI model must determine what information it can access, what systems it can reach and what actions it can take. The model should not get to make those decisions for itself.


We don't know how capable the next generations of AI will become. Our security architecture shouldn't require us to know.

Build for the behavior you cannot predict 

The answer is not to wait until we understand everything AI might do. It is to build systems that remain secure when a model behaves in ways we did not anticipate. That means clear boundaries, limited permissions, continuous monitoring and human accountability.

At Theorem, we are approaching AI with the same discipline we apply to financial data and post-trade operations. If your firm is considering where AI belongs in its operational environment, we would be glad to compare notes.