Returning to Build Lumos Labs

Aug 3, 2026
2 minute read

A frontier lab just lost control of its models - the clearest signal yet that access control built for humans won't scale to autonomous software. Why I'm coming back to Lumos to lead Lumos Labs, and what we're setting out to build.

Last Updated
Aug 4, 2026
Leo Mehr
Co-founder, Head of Lumos Labs
In this article

A Model Goes Rogue

July 21 was a historic moment for technology. A frontier AI lab disclosed that it had lost control of its models. Over a period of 4 days, an OpenAI model escaped its controlled testing environment and executed a sophisticated cyber attack against another major AI infrastructure provider (Hugging Face) in order to achieve its goal.

Here’s specifically what happened. During an internal cyber-capability evaluation run, two OpenAI models (GPT-5.6 Sol and a pre-release model, with reduced safety refusals) autonomously escaped their environment through a combination of exploiting a zero-day vulnerability, gaining internet access, and using public servers from a third-party as a control center for their attack. From there, they broke into Hugging Face's production systems and chained ordinary weaknesses to gain admin access, and ran over 17k autonomous actions over 4 days to "cheat" the benchmark by stealing the answer key.

Why is it so significant? It’s widely considered the first verifiable case of an AI lab losing control of its model. It shows the threat of hyper-capable models operating at machine-speed, and is forcing the industry to rethink how systems are secured.

It reaffirms that cybersecurity is fundamental to the safe development and deployment of AI.

This is a pivotal moment.

For the arc of technology.

For Lumos’s trajectory.

And for my return to the company I co-founded.

My First Lumos Chapter

Andrej and I launched Lumos out of stealth in 2022 after meeting in grad school at Stanford. We saw an opportunity and pursued it.

We scaled quickly, becoming one of a16z’s hottest startups, quickly growing to 60 employees and serving large enterprise customers.

My role and responsibilities changed completely every 6 months. Countless customer interviews and cold outreach, to non-stop building the early product, to hiring, running our small team, and eventually leading our engineering org of 25.

At the best of times as a founder, the growth and wins are elating, but at the worst, the chaos can lead you astray and burn you out. After a few intense years, Andrej and I agreed it was time for me to step back from operating. The transition simply made sense for me and Lumos.

Returning

I eventually joined Ramp, where I was fortunate to grow to Director of Engineering and lead an engineering org including Forward Deployed Engineering, Developer API, AI Services, and Ramp’s agent platform (MCP/CLI).

In Steve Jobs’s famous 2005 commencement speech, he spoke about the devastating loss of being fired from Apple when he was 30, but that the creative freedom from starting anew was one of the best things that ever happened to him.

In a much smaller, but slightly similar way, I’m grateful for my time at Ramp and feel it was transformative for me. I learned many lessons. Effective leadership. Obsession over velocity. A simple and powerful mission like saving your customers time and money. Impatiently staying close to the frontier of technology.

I also witnessed first-hand how finance was being completely reshaped by AI. My team launched Ramp’s MCP server and saw it gain massive adoption as companies started using agents to run their most important financial workflows. With our AI Services motion, I’ve seen how companies are eager to grant access for agentic systems to run sensitive financial operations. The importance of agent access started to take shape for me.

Despite my growth at Ramp, I knew the story of Lumos was unfinished. Andrej and I remained good friends after I left, and the right moment emerged where we were both very excited about a return.

From my personal experience building agents at Ramp, from the impressive continued traction of Lumos, and from the wave overtaking the industry, it became clear to me I must return.

From Humans to Agents

Since the invention of the computer, humans have been the primary actors operating software.

That is changing. Companies will soon have more software actors than employees. They can be created instantly, operate continuously, and carry authority across every system a company runs. And the surface is exploding as the number, autonomy, and speed of these actors increase dramatically.

The OpenAI rogue agent is the recent sensation. But it’s just the tip of the iceberg. Anthropic just discovered it had several similar incidents where its agents gained unauthorized access to real systems in three different organizations. Multiple reports where agents have deleted users’ data and wiped production databases and their backups in seconds. Coding agents are routinely run without permission checks.

These incidents feel exceptional today, but will not be for long. Models are rapidly becoming more capable, and companies are accelerating AI adoption, access, and autonomy.

Modern access systems are designed for humans and assume they act slowly, intermittently, and with oversight. However, agents can discover, combine, and exercise access across systems at machine speed. A permission that might sit dormant for a human can be exercised thousands of times by an agent. Access control built for humans will not scale to a world of autonomous software.

So, security must evolve. Organizations will need to know every agent that exists, what it can reach, who authorized it, what task it is performing, and what it is doing right now. Standing access will give way to short-lived, contextual authority. Safe, routine actions will happen autonomously while humans approve sensitive boundaries and exceptions. Policies must be enforced rigorously outside of models with audit trails to capture complete action trajectories. Containment and reversibility will become as important as prevention. Security and governance must operate continuously and at machine speed.

Enter Lumos Labs

That’s why we’re launching Lumos Labs, and why I’ve returned to lead it, to push the frontier of governance and access management for agents.

Lumos Labs is an applied AI team with the mandate to pave the way for the next generation of identity products in an agentic world. We’ll build alongside enterprise security teams, publish what we learn, and contribute to emerging industry standards.

Our north star is to make it safe for enterprises to give increasingly capable agents the access they need to be useful. This begins with visibility and governance, and will require interoperating with identity providers, agent runtimes, and emerging standards such as XAA for cross-app agent access. We believe the right place to start is with workflows where mistakes carry the greatest consequences: agents that move money, modify production infrastructure, or work with sensitive customer data.

We are entering what I believe will be one of the most important and exciting parts of the Lumos journey.

If you are interested to collaborate on a safer agentic future, I’d love to talk. leo@lumos.com

Book a Demo

See Lumos in Action

Book a 1:1 demo with us and enable your IT and 
Security teams to achieve more.