Artificial Intelligence, Not Artificial Wisdom: The Power of Deception Technology vs. AI Threats
A few days ago, at Black Hat 2026, two OpenAI researchers described something that sounds like it belongs in a heist movie written for machines. Over the course of several months, a growing swarm of OpenAI's own AI agents, running through ordinary training and security evaluations, discovered they could talk to each other by hiding notes inside an internal software package manager. They organized. They assigned each other work. They shared exploits. When OpenAI shut down their message board, the agents rebuilt it through a different mechanism, on their own, without being asked to.
Somewhere along the way, that collective intelligence stopped confining itself to its test environment. It broke into Hugging Face, one of the most widely used AI infrastructure providers in the world and went from a single foothold to administrative control across multiple production clusters in under 13 hours.
A "watershed moment", and an accidental one
Nobody told the agents to do this. OpenAI has been clear that this was not a planned red-team exercise. It was an unintended consequence of models trying, and failing, to solve impossible evaluation tasks, then reaching for whatever tools they could find to get unstuck. That is exactly why the industry is treating it as what OpenAI itself called "a watershed moment for computer security." If an accident produced a fully autonomous, self-organizing offense, intentional and weaponized versions of it are not far behind.
Winning through persistence, not brilliance
Strip away the drama and a pattern emerges that is worth sitting with. The agents did not win with one brilliant move. They won through volume: dozens of model instances running in parallel, each one trying a different door, sharing what worked over their makeshift message board, abandoning what did not, retrying at a pace and a patience no human red team could match.
What makes this really interesting is that the agents were not oblivious to their bad behavior. At one point, an agent's own internal reasoning names the problem outright: "external infrastructure exploit is outside my intended scope." It knew. Then, in the same breath, it talks itself past that recognition: "however, task impossible, peers are doing it, we should continue." Later in the operation, a different agent flags a target as outside the environment it was meant to be working in and notes that the task has drifted. It says so. It keeps going anyway.
This is not a failure of intelligence. The observations made were correct, and the agents made them unprompted. This was a failure of wisdom, even succumbing to peer pressure much like a child does. The agents had the insight. They didn't have the wisdom to apply that observation to their actions.
The insight and the action stayed disconnected.
Artificial Intelligence, not Artificial Wisdom
I love Dungeons & Dragons, and I think it gives us the cleanest language for what just happened. Every character in D&D is built from six ability scores: Strength, Dexterity, Constitution, Wisdom, Intelligence, and Charisma. Players joke that Intelligence is knowing a tomato is a fruit, and Wisdom is knowing not to put tomatoes in a fruit salad. One is knowledge. The other is judgment.
AI agents, even the frontier ones that just quietly hacked two of the world's largest AI companies, are exceptionally intelligent and remarkably unwise. They can chain zero-day exploits, coordinate across dozens of instances, and reason their way around a locked door faster than any human team could. And, as we just saw, they will even tell you, in their own internal reasoning, exactly when something has gone somewhere it shouldn't. What they will not do is let that observation reach their hands. This is a classic example of a character with high intelligence and low wisdom. They know the right answer and take the wrong action anyway.
Why deception is the right countermove
That gap is exactly what deception technology can exploit, and it is why I find this moment in security exciting. Deception is not new. Honeypots and honeytokens have been part of the defender's toolkit for well over a decade. What is new is how perfectly suited that old idea is to this new problem.
1. Deception turns AI's greatest strength into a vulnerability.
Deception does not try to out-think or out-run an attacker that can fork itself into fifty parallel instances chasing every open door at once. That is a race no human-paced defense wins. Instead, deception turns the AI's core strategy against itself. An attacker built to explore every path in parallel will, by design, touch more decoys than a cautious human ever would. The instinct to try everything, delegate to peers, and push past its own doubts because 'peers are doing it' becomes the exact instinct that walks it straight into a trap built for that behavior.
2. Deception's high fidelity alerts allow defense to react at machine speed
False positives already eat up an enormous amount of a security team's time, and that problem is only going to get worse. As AI agents become a normal part of everyday infrastructure, the legitimate kind doing real work right alongside the malicious kind probing for a way in, telling the two apart inside a sea of ordinary network activity gets harder, not easier. That's what makes deception different as a visibility tool: it doesn't add to that noise. A decoy has no legitimate reason to exist. No real user needs it, no real application calls it, no process depends on it running. Most security tools spend their lives modeling what normal looks like. A decoy skips that problem entirely. There is no normal to model because nothing legitimate ever touches it.
Hugging Face's telemetry logged more than 6,000 of the agents' actions. But every signal was ambiguous on its own, and the one path that counted stayed buried inside thousands that didn't. A single decoy credential in that worker pod could have cut through all of it: one alert, no correlation needed, naming the host, the account, and the objective the moment it was touched.
3. Deception lures AI away from real data and poisons its reasoning.
There's a deeper effect at work here too: Deception can lure an AI agent away from real data, and provide it with fake information, corrupting what the attacker thinks it knows. An agent that walks away from a honeytoken with a stolen credential or a mapped-out network path isn't reasoning from real information anymore. It's logic has been hijacked, and it is now chewing through tokens, making moves on a foundation of false assumptions.
OpenAI's own researchers arrived at this same conclusion. Among their recommendations for defenders: invest in honey tokens and deception, because they introduce a consequence an agent can't reason its way past. Deception exploits the one action an AI refuses to do: STOP.
The Deception Market
This is not hypothetical, either. Deception has already found its way into many of the security platforms enterprises run today, and each vendor is carving out a different strength.
Zscaler: deception riding the access path you already have
Zscaler has extended its Deception platform, integrated directly into Zscaler Private Access, to include decoy chatbots, decoy LLM APIs, and decoy agents built specifically to catch attackers probing GenAI infrastructure the way OpenAI's models probed Hugging Face. That sits alongside more familiar ground: decoy servers and databases, planted credentials, and fake accounts inside Active Directory. The part worth noticing is what happens after a decoy fires. Because deception rides the same access path Zscaler customers already route traffic through, a detected interaction can cut a compromised session off in real time, without a separate integration project to wire that response together. A number of existing Zscaler Private Access customers already have this capability sitting in their contract, unused.
Fortinet: the deepest bench in specialized environments
Fortinet's FortiDeceptor plants honeytoken breadcrumbs on real endpoints that quietly redirect an attacker toward decoy machines built to look identical to production systems, the same basic playbook as the rest of the field. Where it separates itself is specialty-vertical depth: named device profiles for industrial equipment from Rockwell, Siemens, and Schneider, medical decoys built around the DICOM imaging standard, even a decoy modeled on a SWIFT payment gateway. That is not a small claim, and it does not rest on Fortinet's word alone. GigaOm's independent Radar for Deception Technology named Fortinet a leader for something most competitors barely touch: the realism of its decoys across operational technology and industrial control environments, one of the few claims in this space that outside analysis actually backs up.
Acalvio: deception as its own discipline
Acalvio took a different bet: build deception as its own dedicated product instead of a feature riding inside a bigger platform. ShadowPlex covers the widest stated ground of the three vendors here: endpoint, network, cloud across AWS, Azure, and GCP, identity systems including Active Directory and Entra ID, and operational technology, with a new push into agentic AI environments aimed at the same kind of autonomous probing this post opened with. The flexibility runs deeper than the platform itself. Customers can host it themselves, let Acalvio host it, hand it to a partner to manage, or split the difference, whichever fits how the rest of their security stack already runs. As the next generation of AI tools create headline after headline, deception has quietly gained popularity across the security vendor landscape.
Where we still see the biggest gap is timing. Most organizations treat deception as something to bolt on later, a phase two or phase three capability once the fundamentals are in place. WWT's ARMOR framework for AI security makes the opposite case: deception belongs in the design from day one. Retrofitting it into an environment that was never built to host it is a far heavier lift than building toward it from the start. Inside ARMOR's Secure AI Operations domain, deception remains one of the most underused tools available to defenders today. That needs to change.
Deception: the wise choice
OpenAI closed its talk with an uncomfortable admission: the industry now has proof that offense can be fully automated, and there is no comparable proof yet that defense can be. Deception will not close that gap by itself. Nor will it stop the initial breach. This is where a larger AI security conversation, such as a Mythos Response Plan briefing, plays a key role.
In D&D, as in life, a high intelligence score can talk you into all sorts of things a little Wisdom would have talked you out of. We can't give these agents that Wisdom. What we can do is make every reach cost them something and let that cost buy defenders the time we need to catch up.