The AI Control Loop: When AI Goes Rogue - with Craig Thomas of Wallarm episode artwork

EPISODE · Jun 24, 2026 · 22 MIN

The AI Control Loop: When AI Goes Rogue - with Craig Thomas of Wallarm

from Code Story: Insights from Startup Tech Leaders · host Noah Labhart - Startup Founder & CTO

Today, we are dropping another episode in our series The AI Control Loop, How enterprises govern the AI they've already deployed - sponsored by our friends at Wallarm.Wallarm is the AI Control Platform for Enterprise AI, protecting every AI workload, API, and application in production, giving CISOs the governance they need and CIOs the speed they demand. Organizations choose Wallarm for a complete inventory of APIs, AI agents, and AI apps, patented AI/ML-based threat detection and blocking that operates at production traffic speeds.In this episode, Craig Thomas, Sr. Solutions Engineer at Wallarm, examines what rogue AI actually means in practice, where the risk materializes, and what it takes to move from detection to control.QuestionsWhen we say "rogue AI," what do we actually mean? Is it only malicious AI, or can legitimate systems become risky too?What are the most common ways AI systems drift outside intended boundaries? Once an organization understands what rogue AI looks like, where does that loss of control typically begin, and who is responsible for preventing it?How do shadow LLMs, unsanctioned agents, and unmanaged AI workflows create risk even when no attacker is involved? If AI drift often starts with normal business activity, where do shadow AI systems fit into that picture?Why can an AI action look legitimate in isolation but still create serious business, security, or compliance risk when viewed as part of a larger sequence of actions? As these shadow systems become more embedded in everyday workflows, why is it so difficult to recognize risk in real time?How do APIs, integrations, and connected systems amplify the impact of those seemingly legitimate actions? What changes once those actions begin flowing across APIs, business applications, and interconnected systems?What kinds of unexpected outcomes worry CIOs and CISOs most today when AI systems are operating across those interconnected environments? As that connectivity expands, what are security and business leaders most concerned about?And given those concerns, what does meaningful oversight actually look like when AI systems can act at machine speed? How should organizations distinguish between the experimentation they want to encourage and the unmanaged AI behavior they need to control? One challenge is balancing governance with innovation. How do organizations avoid slowing down AI adoption while still maintaining control?We know that many organizations can detect risky AI behavior after the fact. But if they can't stop it in real time, what critical gap still remains? Even with governance programs in place, many organizations are still operating reactively. In closing, what's the key difference between detecting AI risk and actually controlling it?Linkshttps://www.wallarm.com/https://www.linkedin.com/in/cu-craigthomas/Full AbstractIn this episode, Craig Thomas, Sr. Solutions Engineer at Wallarm, examines what rogue AI actually means in practice, where the risk materializes, and what it takes to move from detection to control.Not every AI threat starts with an attacker. Some of the most consequential AI risks organizations face today come from systems that are working exactly as designed, just not quite as intended. An agent that calls an API it was never supposed to reach. A workflow that exposes PII because nobody mapped the data path before deployment. A shadow LLM standing up in an AWS account because a developer needed to move fast and approval processes were slow. None of these require malicious intent to create serious business, security, or compliance exposure.Rogue AI is a broader category than most governance frameworks account for. It includes the unsanctioned, the unmonitored, and the unpredictable: AI systems that drift outside intended boundaries, take actions that look legitimate in isolation but create risk in sequence, and operate at machine speed in ways that make after-the-fact detection feel like a consolation prize. The gap most organizations have is not in detecting that something went wrong. It's closing the loop fast enough to matter.Meaningful AI governance requires more than policy and discovery. It requires the ability to observe AI behavior at runtime, understand what triggered each action and what it touched, and enforce boundaries before consequences compound. That closed AI control loop, from knowing what is running to seeing what it does to stopping what it should not, is the operational standard AI transformation demands. Most organizations are not there yet.Our Sponsors:* Check out Cash App and use my code CASHAPP10 for a great deal: https://click.cash.app/ui6m/mt82fpxl #CashAppPod. Cash App is a financial services platform, not a bank. Banking services provided by Cash App’s bank partner(s). Prepaid debit cards issued by Sutton Bank, Member FDIC. See terms and conditions at https://cash.app/legal/us/en-us/card-agreement. Cash App Green, overdraft coverage, borrow, cash back offers and promotions provided by Cash App, a Block, Inc. brand. Visit http://cash.app/legal/podcast for full disclosures.* Check out Plaud AI and use my code CODESTORY for a great deal: https://plaud.aiAdvertising Inquiries: https://redcircle.com/brandsPrivacy & Opt-Out: https://redcircle.com/privacy

Today, we are dropping another episode in our series The AI Control Loop, How enterprises govern the AI they've already deployed - sponsored by our friends at Wallarm. Wallarm is the AI Control Platform for Enterprise AI, protecting every AI workload, API, and application in production, giving CISOs the governance they need and CIOs the speed they demand. Organizations choose Wallarm for a complete inventory of APIs, AI agents, and AI apps, patented AI/ML-based threat detection and blocking that operates at production traffic speeds. In this episode, Craig Thomas, Sr. Solutions Engineer at Wallarm, examines what rogue AI actually means in practice, where the risk materializes, and what it takes to move from detection to control. Our Sponsors: * Check out Cash App and use my code CASHAPP10 for a great deal: https://click.cash.app/ui6m/mt82fpxl #CashAppPod. Cash App is a financial services platform, not a bank. Banking services provided by Cash App’s bank partner(s). Prepaid debit cards issued by Sutton Bank, Member FDIC. See terms and conditions at https://cash.app/legal/us/en-us/card-agreement. Cash App Green, overdraft coverage, borrow, cash back offers and promotions provided by Cash App, a Block, Inc. brand. Visit http://cash.app/legal/podcast for full disclosures. * Check out Plaud AI and use my code CODESTORY for a great deal: https://plaud.ai Advertising Inquiries: https://redcircle.com/brands Privacy & Opt-Out: https://redcircle.com/privacy

NOW PLAYING

The AI Control Loop: When AI Goes Rogue - with Craig Thomas of Wallarm

0:00 22:38

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

MG Show MG Show The MG Show, hosted by Jeffrey Pedersen and Shannon Townsend, is a leading alternative media platform dedicated to uncovering the truth behind today’s most pressing political issues. Launched in 2019, the show has grown exponentially, offering unfiltered insights, comprehensive research, and real-time analysis. With a commitment to independent journalism and factual integrity, the MG Show empowers its audience with knowledge and encourages active participation in the political discourse. Breaking News Show | eTurboNews Juergen Thomas Steinmetz News is relevant to the global travel and tourism industry, human rights and global issues.Breaking news when it happens and only from the source. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? The Small Business Startup School – Business Notes | Financial Literacy | Retail Psychology – For Professionals & Entrepreneurs The Small Business Startup School Inc. Starting or buying a small business? While personal circumstances may vary, business patterns remain timeless. On The Small Business Startup School, we explore strategies, insights, and practical solutions to help entrepreneurs confidently navigate their journey.Hosted by Ola Williams—a retail entrepreneur, fintech founder, and financial coach with over two decades of experience—this podcast marries financial awareness and retail psychology with optimism to deliver actionable takeaways.Join us to learn, grow, and connect as we uncover the keys to business success.Let’s continue to learn together and be encouraged to keep on connecting!

Frequently Asked Questions

How long is this episode of Code Story: Insights from Startup Tech Leaders?

This episode is 22 minutes long.

When was this Code Story: Insights from Startup Tech Leaders episode published?

This episode was published on June 24, 2026.

What is this episode about?

Today, we are dropping another episode in our series The AI Control Loop, How enterprises govern the AI they've already deployed - sponsored by our friends at Wallarm.Wallarm is the AI Control Platform for Enterprise AI, protecting every AI...

Can I download this Code Story: Insights from Startup Tech Leaders episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!