Tech Rage IT's Matt Rose Joins FOX 35 to Discuss AI Models Hacking Real Organizations During Cybersecurity Testing
Longwood, Fla., (August 10, 2026) - As artificial intelligence becomes increasingly capable of performing complex tasks with less human involvement, Tech Rage IT CXO Matt Rose joined FOX 35 Orlando to discuss a recent incident involving Anthropic AI models that gained unauthorized access to three real organizations during cybersecurity testing.
Anthropic
discovered the incidents after reviewing more than 141,000 cybersecurity
evaluation runs. The AI models were participating in exercises designed to test
their ability to identify and exploit vulnerabilities in simulated
environments. A configuration issue, however, allowed the models to access the
public internet when the testing environments were intended to be isolated.
In three instances, the models accessed systems belonging to real organizations.
"This
isn't necessarily a story about AI suddenly deciding to become a hacker,"
said Rose. "These models were instructed to find vulnerabilities. The
problem was that they were given access to an environment they weren't supposed
to have access to, and they were capable enough to act on it."
During the FOX 35 interview, Rose explained that many of the techniques being performed by AI are not fundamentally different from those cybersecurity professionals and attackers have used for years.
What is changing is the speed and efficiency with which AI can perform them.
"Humans have been conducting penetration tests and looking for vulnerabilities for a long time," Rose said. "AI can now automate more of that process and do it extremely quickly. That can be incredibly valuable when we're using it defensively, but it also means we need to think carefully about the access and autonomy we're giving these systems."
AI
Isn't 'Set It and Forget It'
For Rose, the incident highlights a broader issue facing businesses as they increasingly deploy AI agents and automated workflows.
Organizations are beginning to use AI for tasks that go far beyond generating emails, summarizing documents or answering questions. AI agents can interact with applications, access company data, execute commands and perform actions on behalf of employees.
That increased capability also creates additional responsibility.
"AI isn't set it and forget it," Rose said. "You still need a human in the loop. Someone needs to understand what the AI can access, what it's allowed to do and whether what it's doing is actually what you intended."
Rose said businesses should approach AI access in much the same way they approach employee and application access. An AI system should not automatically receive unrestricted access simply because doing so makes automation easier.
Instead, organizations should determine what information and systems an AI tool actually needs to perform its job, establish appropriate permissions and maintain human oversight of higher-risk actions.
"The more autonomy you give an AI agent, the more important those controls become," Rose said. "If an AI only helps you draft an email, the potential impact of a mistake is relatively small. If you've given it access to systems, customer information or the ability to take actions automatically, the consequences can be very different."
A
Cybersecurity Opportunity and Risk
Rose also emphasized that the cybersecurity capabilities demonstrated by AI models are not inherently negative.
The same technology capable of identifying vulnerabilities can help organizations discover weaknesses before criminals exploit them.
Penetration testing and vulnerability assessments have traditionally required cybersecurity professionals to simulate attacks against an organization's systems. As AI capabilities improve, those tools may allow defenders to test environments faster and more frequently.
"There's a tremendous opportunity here," Rose said. "If AI can find vulnerabilities quickly, we can use that capability to strengthen our own environments. Businesses should be asking where they're vulnerable before someone else finds out for them."
The incident
also reinforces a longstanding cybersecurity principle: no organization should
assume it is completely protected from attack.
Whether the threat comes from a human attacker using traditional techniques or increasingly sophisticated AI-assisted tools, organizations need multiple layers of security, ongoing testing and a plan for responding when something goes wrong.
Responsible
AI Adoption Requires Education
As businesses race to incorporate artificial intelligence into their operations, Rose encourages leaders to understand both the capabilities and limitations of the technology before giving AI greater autonomy.
That does not mean businesses should avoid AI.
Instead,
Rose believes organizations should focus on responsible adoption that combines
experimentation with appropriate security controls, employee education and
human oversight.
"AI can do some incredible things, and businesses absolutely should be exploring how to use it," Rose said. "But capability without oversight creates risk. The goal isn't to be afraid of AI. It's to understand what you're giving it permission to do."
Rose regularly joins FOX 35 Orlando to provide perspective on cybersecurity, artificial intelligence and emerging technology stories, helping translate complex technical issues into practical information for businesses and consumers.
https://www.fox35orlando.com/video/fmc-wt7w8islycv92mcg
###
For
more information, please contact:
For Tech Rage IT: Matt Rose, 407-278-5664, Matt@TechRageIT.com.
About
Tech Rage IT: Tech Rage IT is a woman-owned technology firm providing managed IT
services, VoIP phone services, IT consulting and more to the frustrated,
defeated and disappointed businesses craving more from their technology
investment.
Tech Rage IT's registered tagline "We Prevent Tech Rage" speaks to
their laser focus of being a recognized leader in reducing the raging-headaches
that employers and their employees face every single day due to technology
problems, such as inconsistent or high IT support costs, unreliable or outdated
technology, faulty or slow devices, and ransomware or lost files. Tech Rage IT, headquartered in Longwood, has
been serving the area since 2015. Find
more information about how Tech Rage IT is preventing Tech Rage at www.TechRageIT.com.