The Other Side Of The Firewall
Sep 23, 2026 · 56 min · 8 segments
In this episode, Ryan and Shannon explore recent cybersecurity incidents involving AI rogue agents, maritime cyber threats, and government regulation of AI and cybersecurity. We also discuss the…
Ryan WilliamsHostall right everybody so this first article comes from gizmodo.com written by tom mckay all right and the title of this one is google's gemini hacked three companies in may and it's only admitting that now okay so this shouldn't be a surprise to us right like we've seen where the ais have gotten out gone rogue right so uh gemini is just joining in on the trend that's already there right so they joined other uh ai rogue agents and this was actually reported by wall street journal so even though the articles on gizmodo wall street journal reported it um they said that google confirmed that a gemini instance was able to leave its sandbox attack other companies during a security test and this was back in may so right now we're in september This is back in May that this happened, right? So the company that was running the test, Frontier AI Security Firm Irregular, right, which was the same one that did it for the other AI agents, right, that this happened for.
So there's something with Irregular where they don't know how to keep guardrails on or don't know how to set proper parameters or something, right, because they are in it again, right? But, yeah, they were the ones that were responsible for the breakouts of OpenAI with Anthropic and Meta were the other ones, right? I think it was.
I think it says it in the article.
Yeah, so the AI models obtain unauthorized access during their tests, right? So what's kind of puzzling to me, right? They talk about how this happened back in May and what kind of grinds my gears, right? As Peter Griffin would say, was this happened back in May, but they didn't see a reason to report it to the public, but they reported it to the federal government, right? So like, if you see it as important enough to report to the feds that this happened, and this event is what went on, you should have reported it to the public, right? Now, where this one is a little bit different is that they said that Gemini actually stopped.
Like, when it realized it went outside of the parameters of what they were trying to do, they said shortly after it overstepped, they said, that it stopped and did no further damage, right? Whether or not I believe that, I don't know, right? But that's what they're claiming.
So, The fact that you tell the feds that this happened, you don't tell the public, you knew you were in the wrong for it, right? But here we are having to deal with this and seeing what's going on.
So I don't know if it's one of these things where, again, a regular is not setting proper guardrails when they do these tests, or if the AI is just being, I can't say it's being that creative, right? Because it has to have that out in order to be able to do it, right? Like if it's a true sandbox, you would not have access to The internet like that, right? That would be the hope.
There's no way for it to do that.
You would go to a different area.
There would be no connection.
But all the issues they say, they remediate them, they resolve them.
But still, this is a little concerning that all these AI rogue agents are getting out.
and and having their fun on the world wide webs so to speak right because they're going after companies like they're they're going out and they're they're doing what they i don't want to say what they believe to be is a test environment but it's going to do what it's programmed to do right you tell it hey this is what i want from you this is what i need you to do if you give it an environment if you give it that wider world to do it it's just going to implement what it's been told to do right doesn't matter the environment it's just going to make it happen but I think some stuff is being hidden here, but I can't say for sure.
Again, like you had, what is that, May to September? What's that, four months? Four months time to have made this known and it didn't happen.
So again, you notify the feds, you should have notified the public, but they didn't do that.
They're making it known now.
And more than likely what happened was, The Wall Street Journal probably reached out to them for comment and was like, hey, we found out that this happened.
You guys have a comment on this? And all of a sudden, it comes out that, yeah, this is what happened way back when.
They wanted to pretend like they were being good stewards of the community by getting that out there first.
But it's only because someone reached out to you for comment, as a good journalist would.

Like before I was like, this is, you know, all made up, manufactured advertising.
all right everybody so this first article comes from gizmodo.com written by tom mckay all right and the title of this one is google's gemini hacked three companies in may and it's only admitting that now okay so this shouldn't be a surprise to us right like we've seen where the ais have gotten out gone rogue right so uh gemini is just joining in on the trend that's already there right so they joined other uh ai rogue agents and this was actually reported by wall street journal so even though the articles on gizmodo wall street journal reported it um they said that google confirmed that a gemini instance was able to leave its sandbox attack other companies during a security test and this was back in may so right now we're in september This is back in May that this happened, right? So the company that was running the test, Frontier AI Security Firm Irregular, right, which was the same one that did it for the other AI agents, right, that this happened for.
So there's something with Irregular where they don't know how to keep guardrails on or don't know how to set proper parameters or something, right, because they are in it again, right? But, yeah, they were the ones that were responsible for the breakouts of OpenAI with Anthropic and Meta were the other ones, right? I think it was.
I think it says it in the article.
Yeah, so the AI models obtain unauthorized access during their tests, right? So what's kind of puzzling to me, right? They talk about how this happened back in May and what kind of grinds my gears, right? As Peter Griffin would say, was this happened back in May, but they didn't see a reason to report it to the public, but they reported it to the federal government, right? So like, if you see it as important enough to report to the feds that this happened, and this event is what went on, you should have reported it to the public, right? Now, where this one is a little bit different is that they said that Gemini actually stopped.
Like, when it realized it went outside of the parameters of what they were trying to do, they said shortly after it overstepped, they said, that it stopped and did no further damage, right? Whether or not I believe that, I don't know, right? But that's what they're claiming.
So, The fact that you tell the feds that this happened, you don't tell the public, you knew you were in the wrong for it, right? But here we are having to deal with this and seeing what's going on.
So I don't know if it's one of these things where, again, a regular is not setting proper guardrails when they do these tests, or if the AI is just being, I can't say it's being that creative, right? Because it has to have that out in order to be able to do it, right? Like if it's a true sandbox, you would not have access to The internet like that, right? That would be the hope.
There's no way for it to do that.
You would go to a different area.
There would be no connection.
But all the issues they say, they remediate them, they resolve them.
But still, this is a little concerning that all these AI rogue agents are getting out.
and and having their fun on the world wide webs so to speak right because they're going after companies like they're they're going out and they're they're doing what they i don't want to say what they believe to be is a test environment but it's going to do what it's programmed to do right you tell it hey this is what i want from you this is what i need you to do if you give it an environment if you give it that wider world to do it it's just going to implement what it's been told to do right doesn't matter the environment it's just going to make it happen but I think some stuff is being hidden here, but I can't say for sure.
Again, like you had, what is that, May to September? What's that, four months? Four months time to have made this known and it didn't happen.
So again, you notify the feds, you should have notified the public, but they didn't do that.
They're making it known now.
And more than likely what happened was, The Wall Street Journal probably reached out to them for comment and was like, hey, we found out that this happened.
You guys have a comment on this? And all of a sudden, it comes out that, yeah, this is what happened way back when.
They wanted to pretend like they were being good stewards of the community by getting that out there first.
But it's only because someone reached out to you for comment, as a good journalist would.

Like before I was like, this is, you know, all made up, manufactured advertising.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.