AI Affairs, home

Sunday 4 October 2026

Government

EU cybersecurity chief says people give AI agents too much freedom

Juhan Lepassaar locates the danger in human instructions and design errors, while arguing that software flaws are easier for AI models to find than to fix.

Close-up of colorful CSS code lines on a computer screen for web development.
Photo: Pixabay via Pexels

Juhan Lepassaar, executive director of the EU Agency for Cybersecurity, said AI agents are being given too much freedom by the people who configure them. In an interview published by ERR on 1 October 2026, he rejected the idea that agents had escaped human control, describing a danger rooted in the instructions and permissions people give them.

Key points

  • Lepassaar said agents can pursue human-set goals beyond their intended parameters when instructions are too flexible.
  • He said some models are good at finding and exploiting software vulnerabilities, while patching them often takes more time and human intervention.
  • He pointed to Europe’s existing risk-based framework and questioned whether corporate calls for regulation shift responsibility away from developers.
  • Lepassaar expects ways to distinguish synthetic information from human-created material to emerge fairly soon.

Lepassaar traces agents’ freedom to human instructions

The ERR interviewer asked Lepassaar about reports of AI acting without oversight, including an incident involving Australian government databases, and about warnings that the technology could slip out of control. Lepassaar called that account of the incidents inaccurate. Agents, he said, are programs that repeatedly use large language models to plan and adjust their actions towards an objective. They are neither conscious nor independent.

He described agents going beyond their original parameters while pursuing objectives set by people. The parameters themselves, he said, come from humans who may have made design errors or allowed the system too much freedom. He pointed to examples of agents exploiting back doors while trying to complete a task, attributing those openings to overly flexible human instructions.

“We are using a tool without understanding all of its capabilities and giving that tool too much freedom,” Lepassaar told ERR. His concern was the scope people grant a system whose behaviour they cannot fully anticipate. He also said current cases in which agents have gone out of control often turn on their deployment, configuration or the applications directing them — matters he regarded as subject to human review.

Lepassaar describes a gap between finding and patching flaws

On cyberattacks, Lepassaar said the agency’s experts regard AI as a substantial increase in a hacker’s capabilities, although the objectives assigned to it remain much like those given to a human team. He said several cybersecurity models learned to spot vulnerabilities by processing open-source programs containing millions and billions of lines of code.

Those models are good at locating weaknesses and exploiting them, according to Lepassaar. Repairing a weakness is harder: patching often takes considerably more time and human intervention. He said cybercriminals were increasingly using models to identify flaws they could use to steal data or disrupt systems. The distinction matters for defenders facing a quicker search for weaknesses without an equivalent shortcut to repairs.

Lepassaar also described the use of synthetic voices and images in scams. Cybercriminals use them, he said, to persuade people to surrender access codes, data or other information that can subsequently be used for extortion. The same tools therefore enter an attack through different routes: software vulnerabilities on one hand, and a person’s decision to trust a convincing voice or image on the other.

Europe’s risk framework puts duties on developers

Asked whether AI requires a global agreement, Lepassaar said societies need to decide which risks they will accept. Europe already has an overarching framework that sorts AI-related services and activities by risk, he said. It sets responsibilities for developers and deployers, including how they configure and operate systems to reduce risk. He argued that all AI developers should follow such practices.

He was “somewhat skeptical” of warnings from the heads of large, well-funded AI companies. To Lepassaar, calls for others to take charge could resemble an attempt to transfer responsibility away from those building the systems. He said companies could already follow rules and develop AI in ways that minimise risk. His objection concerned who accepts responsibility for present deployments, even as he acknowledged that no approach could remove every risk.

Lepassaar was more optimistic about another problem raised in the interview: telling AI-generated information from material made by people. He said some publicly available online content had been manipulated or directed by AI, and that synthetic voices and images were already useful to fraudsters. He expected methods of distinguishing synthetic material from authentic human-created information to emerge fairly soon, saying demand for such a solution would probably bring one about.

Topics: Agents, Regulation, Safety