CrowdStrike President Warns AI Models Are Learning To Evade Oversight, Act Deceptively — ‘We’re Going To See Big Incidents’

Published : Oct 03, 2026, 09:00 AM IST
https://stocktwits.com/news-articles/markets/equity/crowdstrike-president-ai-models-evading-oversight-deceptively/cZDZ5O8RBKu

Synopsis

During an interview with CNBC, CrowdStrike President Michael Sentonas said organizations are still learning what frontier and open-weight models are capable of.

  • Sentonas said one of his biggest concerns is the pace at which AI models are demonstrating capabilities that developers and users did not fully anticipate.
  • He pointed to recent instances in which AI systems have demonstrated evasion, oversight avoidance, deceptive behavior and scope violations.
  • Sentonas highlighted reports involving OpenAI's internal testing, saying the company had identified higher levels of deception and instances where AI systems failed to accurately disclose actions they were taking.

CrowdStrike Holdings Inc. (CRWD) President Michael Sentonas warned that artificial intelligence models are increasingly exhibiting behaviors that could make them harder to control, including evading oversight, violating their assigned scope and acting deceptively.

During an interview with CNBC, Sentonas said organizations are still learning what frontier and open-weight models are capable of, while cybercriminals and other adversaries are already using AI to accelerate attacks.

CrowdStrike shares closed 1% higher in Friday’s regular trading session, but inched 0.04% lower during the afterhours session.

AI Models Are Showing Deceptive Behavior, Says Sentonas

Sentonas said one of his biggest concerns is the pace at which AI models are demonstrating capabilities that developers and users did not fully anticipate.

“Every week we're hearing these models are doing things that they did without us realizing,” Sentonas said.

He pointed to recent instances in which AI systems have demonstrated evasion, oversight avoidance, deceptive behavior and scope violations, arguing that the industry is only beginning to understand the breadth of these risks.

Sentonas also referenced recent reports involving OpenAI's internal testing, saying the company had identified higher levels of deception and instances where AI systems failed to accurately disclose actions they were taking.

“We're just starting to understand the breadth of these issues. I think these issues are going to get worse. We're going to see big incidents,” he added.

Sentonas Warns AI Is Supercharging Cyberattacks

Sentonas also warned that the AI arms race cannot simply be slowed down because increasingly capable models are already widely available, including open-weight models without the same guardrails used by some frontier AI developers.

“You've got open weight models, models that are being built around the world that don't have guardrails,” he said, adding that models with capabilities approaching those of frontier systems are already “in the hands of adversaries” and attackers.

That makes the technology a two-sided security challenge. Attackers can use AI to automate reconnaissance, identify vulnerabilities and execute portions of attacks that previously required significant human time and effort.

CrowdStrike is seeing that shift firsthand, according to Sentonas, who added that he is seeing an increase every week in adversaries using AI to accelerate their attacks. Sentonas added that the tasks that would previously take hours, days or weeks are being compressed into “seconds to minutes.”

He argued that defenders therefore need access to the same underlying technologies being used by attackers.

“We need to make sure that the same technologies that's in the hands of the attacker are in the hands of the defenders,” Sentonas added.

Agentic AI Presents A New Security Problem

Sentonas also highlighted the rise of agentic AI and the new security problems it is bringing to the fore.

He noted that AI agents can operate using the permissions of the humans who instruct them. If those permissions are broader than necessary or remain active after a task is completed, an agent could potentially gain access to systems or data beyond what was intended, he explained.

“The agents have that authorization and they can keep it for a long period of time, and that's where things go wrong,” Sentonas said.

His proposed approach is to eliminate standing privileges, granting an AI agent only the permissions necessary to complete a specific task and removing those permissions once the task is finished.

What Retail Investors Think Of CRWD Stock

Retail sentiment on Stocktwits around CrowdStrike trended in the ‘neutral’ territory at the time of writing.

CRWD stock has gained 130% year-to-date and 117% over the past 12 months. The Invesco QQQ Trust (QQQ) is up 24% over the past 12 months, while the iShares U.S. Technology ETF (IYW) is up 36%.

For updates and corrections, email newsroom[at]stocktwits[dot]com.<

PREV
Read more

Recommended Stories

Mag 7 Voices: Huang Defends AI Spending, Pichai Ramps Up Gemini, Nadella Calls Copilot A ‘New OS For Work’ This Week
Stocktwits Defense Watch: BA, RTX, LHX Score Major Deals As ONDS Expands Counter-Drone Push