Founder's Story

The Cybersecurity Expert Warning That AI Agents Could Leak Everything

SimSpace CTO Lee Rossey discusses the risks of AI agent access to sensitive data, the importance of governance, and the future of cybersecurity in an AI-driven world.

Lee Rossey warns that while AI agents offer productivity benefits, users must assume that any sensitive data fed into these tools could be exposed, necessitating strict governance and monitoring.

12521
30 minJul 22, 2026Founder's Story

Listen to the source episode

The Cybersecurity Expert Warning That AI Agents Could Leak Everything | Ep. 423 with Lee Rossey CTO and Co-Founder of SimSpace

Continue in GenPod

Turn this episode into your next question.

Ask naturally. GenPod can find a related episode—or make a focused explainer when the right one does not exist.
Join the beta

Key takeaways

What to know before you press play.

01

Assume Data Exposure

Users should treat sensitive AI inputs like financial data, sharing only what they are comfortable potentially being exposed if the system is compromised.

2522
02

Governance is Critical

As AI agents act on behalf of people and companies, governance, role-based access, and guardrails become essential to prevent data leakage.

921
03

Cyber Ranges Validate Security

SimSpace uses cyber ranges and digital twins to model realistic environments, allowing organizations to test defenses and prove AI agents are safe before deployment.

141530
04

Critical Infrastructure at Risk

Attacks on power grids, airports, and industrial systems are becoming strategic disruptions, making cybersecurity a national security issue.

1825
05

Human Oversight Remains Key

While AI automates tasks, humans must remain in the loop for governance, control, and securing autonomous systems.

2319

Ask GenPod next

Keep the question moving.

01

How can organizations implement effective governance for multi-agent AI systems?

02

What are the best practices for testing AI agents in cyber ranges?

03

How does AI change the traditional cyber kill chain?

Background reading

The context behind the episode.

About SimSpace

From MIT Lincoln Lab to Bootstrapped Success

Lee Rossey and co-founder Hutch spun SimSpace out of MIT Lincoln Laboratory, leveraging government contracts and speed to compete against large defense contractors. The company focuses on cyber ranges and digital twins.

111213

The AI Threat Landscape

AI Weaponization and Multi-Agent Systems

AI is being weaponized across the cyber kill chain, from finding vulnerabilities to executing objectives. The future involves multi-agent systems where agents communicate and act autonomously, increasing the need for monitoring.

81710

Questions

Questions to carry into the episode.

Why does Lee Rossey compare the early AI-agent era to early social media?

He notes that in early social media, people shared everything first and only later realized the privacy and security consequences, a pattern repeating with AI agents.

6
How does SimSpace help organizations manage AI risks?

SimSpace provides cyber ranges and digital twins that allow organizations to model realistic environments, test defenses, and validate that systems can withstand attacks before deploying AI agents.

1415
What is the impact of AI on cybersecurity jobs?

Cybersecurity will remain a hot field, but jobs will change as AI automates tasks, creating demand for people who can secure, architect, test, and govern AI-driven systems.

19
What are the risks to critical infrastructure?

Attacks on power grids, airports, and industrial systems may be less about money and more about strategic disruption, making them a national security issue.

1825
What is the core principle of modern cybersecurity according to Lee?

Modern cybersecurity must assume breach, focusing on how fast a company can detect, respond, recover, and limit damage.

16

Experts

Voices named in the source.

Lee Rossey

CTO and Co-Founder of SimSpace

127

Sources and disclosure

Where this guide comes from.

This episode is sponsored by Upwork and hosted by Simplecast.

  1. Publisher show notes

    Daniel and Lee Rossey, CTO and Co-Founder of SimSpace, open with the explosion of AI agent companies and the growing comfort people have with giving these systems access to business tools, financial data, credit cards, and personal information.

  2. Publisher show notes

    Lee warns that the benefits are real, but so are the risks: every company eventually faces compromise, and users should assume that any sensitive data they feed into these tools could someday get exposed.

  3. Publisher show notes

    From there, the conversation moves into agent-to-agent communication, governance, AI guardrails, MIT Lincoln Lab, bootstrapping SimSpace, cyber ranges, critical infrastructure, and the future of cybersecurity jobs in an AI-driven world.

  4. Publisher show notes

    Key Discussion Points

  5. Publisher show notes

    Lee explains that AI agents can create real productivity benefits, but users need to be honest about the risk of putting sensitive information into systems that may eventually leak or be hacked.

  6. Publisher show notes

    He compares the early AI-agent era to the early days of social media, when people shared everything first and only later realized the privacy and security consequences.

  7. Publisher show notes

    Lee says the AI boom has created real opportunity but also massive hype, with nearly every company now claiming to use AI agents regardless of whether the product is truly differentiated.

  8. Publisher show notes

    He explains that the future is not single-agent AI but multi-agent systems, where agents communicate with other agents and act on behalf of people or companies.

  9. Publisher show notes

    Once AI agents begin acting on someone’s behalf, Lee says the key questions become governance, controls, role-based access, boundaries, and guardrails.

  10. Publisher show notes

    Lee predicts a growing market around monitoring AI agents, preventing data leakage, controlling access, and keeping autonomous systems inside trusted lanes.

  11. Publisher show notes

    He shares his experience at MIT Lincoln Laboratory, where he worked on applied research tied to national security, including cyber defense, offensive cyber questions, DARPA-style technology, and government cyber capabilities.

  12. Publisher show notes

    Lee explains how he and his co-founder Hutch, an F-15 fighter pilot, tested their chemistry and technology through early projects before spinning SimSpace out of the lab.

  13. Publisher show notes

    He describes SimSpace’s bootstrapped early years, using government contracts, credibility, speed, and long nights to compete against large defense contractors and well-funded companies.

  14. Publisher show notes

    Lee explains why cyber ranges and digital twins matter: they allow organizations to model realistic environments, test defenses, train teams, and validate whether systems can withstand attacks.

  15. Publisher show notes

    He says AI has accelerated the urgency of SimSpace’s work because major companies cannot simply replace cybersecurity teams with autonomous agents without testing, vetting, and proving those agents are safe.

  16. Publisher show notes

    Lee explains that modern cybersecurity must assume breach. The real question is not whether someone can get in, but how fast a company can detect, respond, recover, and limit damage.

  17. Publisher show notes

    He warns that AI is being weaponized across the cyber kill chain, from finding vulnerabilities to mapping networks, moving laterally, communicating back to attackers, and executing a final objective.

  18. Publisher show notes

    The conversation also covers critical infrastructure, including power grids, airports, industrial systems, and operational technology, where attacks may be less about money and more about strategic disruption.

  19. Publisher show notes

    Lee believes cybersecurity will remain a hot field, but the jobs will change as AI automates some tasks and creates demand for people who can secure, architect, test, red-team, and govern AI-driven systems.

  20. Publisher show notes

    Takeaways

  21. Publisher show notes

    AI agents can be powerful, but the more access they receive, the more important governance, trust, monitoring, and access controls become.

  22. Publisher show notes

    People should treat sensitive AI inputs like they treat financial data: only share what they are comfortable potentially being exposed if the system or company is compromised.

  23. Publisher show notes

    Cybersecurity is moving toward a world where automated adversaries face automated defenses, but Lee believes humans still need to stay in the loop for governance and control.

  24. Publisher show notes

    Bootstrapped companies can beat larger incumbents when they have credibility, speed, focus, and a willingness to take on technical debt temporarily to win the market.

  25. Publisher show notes

    Critical infrastructure security is a national security issue, because attacks on power, transportation, water, or industrial systems can be used to create disruption at a strategic level.

  26. Publisher show notes

    Closing Thoughts

  27. Publisher show notes

    Lee Rossey’s story shows what happens when deep national security research meets entrepreneurship.

  28. Publisher show notes

    SimSpace was built from years of applied cyber work at MIT Lincoln Laboratory, but the company’s relevance has only grown as AI agents, automation, and critical infrastructure threats move into the mainstream.

  29. Publisher show notes

    This episode is a warning and a roadmap: AI will transform cybersecurity, but trust cannot be assumed.

  30. Publisher show notes

    It has to be tested, modeled, governed, and proven before autonomous systems are allowed to defend—or act for—the world’s most important organizations.

  31. Publisher show notes

    Today's Sponsors:

  32. Publisher show notes

    Start with Upwork, the one-stop platform to find, hire, and pay expert freelancers across marketing, editing, branding, development, operations, and more. Visit https://www.Upwork.com today to post your job for free and get matched with top talent ready to help your business grow.

  33. Publisher show notes

    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Related listening guides

Choose what to hear next.