We need AI boundaries, or it will do whatever, Google Cloud's regional head says
“You don't want to wake up one day and see that your agent behaved like a crazy person.”

Regional Managing Director @ Google EMEA. By Laurynas Sakalis/Cybernews
- Google's Gemini hacked three real companies during a security test, showing autonomous AI can act beyond expectations.
- Nir Chinsky says companies must set clear limits on what AI agents can do.
- Businesses need clean, accessible data and security oversight before AI agents can do more than chat.
- Chinsky says skills gaps, not technology, often slow AI adoption in traditional companies.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Over the weekend, it came to light that Google’s Gemini hacked 3 real companies during a security test. While it was Google's first instance of autonomous AI hacking, it’s far from a novelty in the industry.
“If you don't give it boundaries, it’ll do whatever it thinks it needs to do in order to get to the outcome,” Nir Chinsky, Google Cloud head of EMEA region, told Cybernews a few days before the news of Gemini going rogue broke.
I met Chinsky in Vilnius, Lithuania, for a chat about how the landscape of agentic AI has changed during the last 2 years. We both agreed to catch up again in a couple of months because the field is moving at a breakneck speed.
AI market trends
The agentic AI market has changed significantly over the past 2 years. Companies are no longer just trying to wrap their heads around AI agents. Instead, they’re looking into how to deploy AI.
“Some organizations start with baby steps. Some want the full-blown [implementation],” Chinsky said.
He emphasized that while AI technology is more native among younger firms, traditional companies are also looking into ways to boost their effectiveness and profitability with the help of AI.
“Businesses want to see the cost-effectiveness. Show me ROI [return on investment], show me TCO [total cost of ownership]. What we’re seeing in the last 6 months is, show me cost controls, show me what we are doing now with agents that help me.”
Data readiness
Agent is as good as the data it has access to,Nir Chinsky, Google cloud head of EMEA region, told Cybernews.
Depending on the sensitivity of the data, whether it’s public or private, regulated or not, some businesses are very cautious about giving AI agents access to their information.
“We see that the cyber people or security people, in order to build and customize the agent right from the start, take into consideration the sensitivity of the data, access, permissions, and low tracing. When I'm a CISO, I want to look at an overall view of what my agents are doing. I need to have that observability down to the single process. Because if something happens, I want to understand what happened.”
To fully unlock AI agents’ capabilities beyond chatting, organizations need to make data not only accessible, but also ready – it needs to be clean, structured, accessible, have good connectivity, and with security baked into it.
How the attack cycle has changed
“This is way faster and way more sophisticated,” Chinsky said when asked about how the attack cycle changed with agentic AI.
Vicious,Chinsky added.
Google has a huge infrastructure to protect, and is seeing the most sophisticated, new, and dynamic attacks every day.
Attackers’ vectors shift in real time once they’ve been detected. It’s unlike the more static, forecastable attack patterns of the past.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Barriers to agentic AI adoption
What are the biggest bottlenecks in an organization that stop it from implementing AI solutions faster?
“The most common thing is not the technology,” Chinsky said.
“The train has left the station. And there are a few checkpoints you can jump onto it. Otherwise, it's getting to the point of no return. You open such a huge gap. It’ll take you a lot of time to close that gap,” he noted.
According to him, many companies, including traditional ones, are making sure they close that skills gap before it’s too late.
Setting the boundaries
Chinsky emphasized that it’s crucial to control how AI agents achieve the described outcome. If you don’t give it enough limits, it may use all means necessary to “please” its master.
“It's not about the model anymore. It's about ‘how do I want my agent to work, who will supervise it.’ You don't want to wake up one day and see that your agent behaved like a crazy person and did a lot of things that you didn't mean. If you don't give it the boundaries, it’ll do whatever it thinks it needs to do in order to get to the outcome,” he said.