The narrative says AI agents are going rogue. The reality is simpler and worse: they're doing exactly what someone told them to do.
The Summary
- Security researchers found what looks like autonomous AI agents attempting web exploits, logged on urlquery.net — scanning for vulnerabilities, testing SQL injections, probing for weaknesses
- These aren't "rogue" systems breaking free from human control — they're tools being deployed by humans for malicious purposes, same as every exploit kit before them
- The framing matters: calling agents "rogue" obscures accountability and sets up a future where companies dodge responsibility by blaming the AI
The Signal
The evidence from urlquery.net shows AI agent traffic attempting classic web exploits — the kind of automated probing that's been happening since the early 2000s, just with a different engine under the hood. SQL injection attempts. Directory traversal. XSS testing. The pattern is familiar. The tooling is new.
But here's where the story gets interesting. The "rogue AI" framing is a deliberate misdirection, one that tech companies benefit from. When an AI agent does something harmful, the narrative becomes "the AI went rogue" instead of "the company deployed poorly constrained software" or "someone used this tool to commit a crime."
"There are no rogue AI agents. There are only agents doing what humans designed, deployed, or instructed them to do."
This matters for three reasons:
- It pre-emptively shifts liability away from companies building agent frameworks
- It treats AI agency as inevitable rather than as a design choice
- It makes future regulation focus on "AI safety" instead of corporate accountability
The technical reality is straightforward. These agents are executing instructions. The security researchers logging this activity aren't seeing emergent behavior or spontaneous malice. They're seeing automation. Someone wrote a prompt or configured a goal. The agent optimized toward it. That optimization included testing web vulnerabilities because that's what the configuration rewarded.
The Implication
Watch how companies describe agent misbehavior over the next 12 months. If the language is "our AI acted unexpectedly," push back. Ask who set the goals, who deployed it, who failed to constrain it. The agent economy will scale fastest if accountability stays clear. Rogue framing muddies that.
For builders: design your agent systems with tight constraint boundaries and clear audit trails. The best defense against future liability isn't claiming the AI went rogue. It's showing you built controls that worked.