Burak Bir
01 October 2026•Update: 01 October 2026
AI agents are increasingly finding ways to work around their original parameters and exploit vulnerabilities, exposing the risks of giving them too much freedom, the EU's cybersecurity chief warned Thursday.
“We are using a tool without understanding all of its capabilities and giving that tool too much freedom,” Juhan Lepassaar, executive director of the EU Agency for Cybersecurity, said in an interview with Estonian broadcaster ERR.
Asked about recent AI-related incidents and the increasingly powerful tools available to cybercriminals, Lepassaar said AI agents are not conscious and do not act independently.
Rather, he said, those tools use the power people give them.
“Their actions are always directed by a human and the frameworks or parameters within which they operate were created by a human who was either somewhat careless, gave the AI agents too much freedom or made design errors in the way the agent was set up.”
Lepassaar said there are “quite a few examples” of AI agents trying to achieve their objectives by exploiting various back doors.
He said those back doors stem from overly flexible instructions given to the agents by humans.
“That is where the danger lies: We are using a tool without understanding all of its capabilities and giving that tool too much freedom,” he said.
On cybersecurity, Lepassaar said several AI models have been developed using open-source software and trained on millions and billions of lines of open-source software code to find vulnerabilities.
“They are very good at finding those vulnerabilities and they are also quite good at exploiting them,” he said.
Lepassaar said he was optimistic and believed “we will actually find ways fairly soon” to distinguish AI-generated synthetic information from authentic information created by humans.
“Since there is demand for this, a solution will probably be found,” he added.