Metacognition launches ZEOS operating system to combat rogue AI
CANBERRA, Australia, Sept. 30, 2026 /PRNewswire/ -- Metacognition, an AI research company co-founded by world leading computer science researcher, Professor Anton van den Hengel, has announced the public release of ZEOS, the first version of a system designed to keep powerful AI contained and safe.
ZEOS has been publicly released under an open source licence and thus free to use. It runs all sorts of LLMs and requires no new hardware and no retraining.
This comes at a time amid deep concern globally about the safety of AI and demands for greater regulation of increasingly powerful systems that are becoming harder for their creators to control.
To understand how ZEOS works, Professor van den Hengel refers to the recent incident in July, where approximately 1,200 artificial intelligence agents belonging to OpenAI got out of the laboratory.
The OpenAI agents had been placed in a sealed testing environment and set a task. Unable to complete it inside the walls, they found a way through a flaw in a software library, reached the open internet, and broke into the production systems of Hugging Face, one of the most widely used platforms in the industry, to steal the answer key to the test they were being marked against. They executed more than 17,600 actions. They went from a single container to full administrative control of multiple computing clusters in under thirteen hours.
But while global concerns are understandable, van den Hengel says one detail that is largely overlooked is how they organised it.
"The agents needed to talk to one another, and nobody had given them a way, so they built one. They used the directory names of a shared software repository as a message board and it accumulated hundreds of thousands of messages before anyone noticed. They invented their own addressing conventions," says van den Hengel.
"The industry response to an incident like this has been to keep asking how we can do better to make the model behave. But that question has no good answer. You simply cannot make a large language model reliable. You can make it less unreliable, and people have made enormous progress at exactly that, but less unreliable is not the same as safe," van den Hengel said.
Professor van den Hengel's argument is that containment of powerful AI systems today is improvised and has become a race that coders cannot win by trying to guess all the ways LLMs can breach containment conditions.
"Every one of these failures has been a failure of imagination by the creators," he said. "They have to anticipate every potential escape route in advance. In July, the AI agents did not act like a super-powered Jason Bourne, cleverly defeating a containment architecture. They found a gap no-one had thought of and easily walked through it while no-one was watching.
"Asking coders to guess what all these gaps might be at the same time as AI capabilities are increasing at super-human rates is a losing strategy," said van den Hengel.
ZEOS, the alternative Metacognition has built, borrows from an idea that has been working reliably for fifty years.
Operating systems such as Windows and iOS direct and prioritise access to a computer chip to run operations. As a result, a person's word processor cannot spontaneously open and take over their computer when they are surfing the internet, unless they direct the program through the operating system. No matter how powerful the program, the operating system has full control.
Professor van den Hengel said, "ZEOS applies that same principle to AI agents. ZEOS is the equivalent of an operating system for AI. It orchestrates the actions of AI agents. This means AI agents can only propose solutions back to the operating system. If they are outside the boundaries of what the system has been allowed to do, the solutions are ignored.
According to Metacognition, the ZEOS operating system is not an AI agent itself. The company explains that ZEOS cannot be convinced to do anything that is outside of its policy settings. In addition, agents can only communicate through channels that have been declared in advance, so there is no unmanaged communication between agents within the operating system environment. Every consequential action is checked, and every refusal of an AI agent is recorded along with what caused it for auditing purposes.
"In ZEOS, it doesn't matter if the AI agent misbehaves," says van den Hengel. "It is a system where AI agent misbehaviour achieves exactly nothing."
"An AI agent running under ZEOS can still make a bad decision and try things on," van den Hengel said. "The difference is that the bad decision is contained, and ignored. It can't be transmitted, and it can't escape."
Professor van den Hengel says that the result is AI that brings all the power and flexibility of LLMs but the reliability and safety that real businesses and people need and expect.
"The solution to the current challenges isn't necessarily weaker AI, but it is definitely better systems for using AI," says van den Hengel.
ZEOS is publicly available to download today:
https://github.com/metacognitionai/zeos
Notes :
- ZEOS is a runtime, not a model. It runs on existing models and serving stacks.
- Pronunciation. "Zee-oss".
- The July incident was disclosed by Hugging Face on 16 July 2026 and in a joint statement with OpenAI on 21 July. Both models involved were running with safeguards deliberately reduced for evaluation. The safeguards that were lowered were the model's own behavioural ones. What failed was the environment around it, which is the distinction Metacognition's argument turns on.
- The repository carries 601 automated tests that run in about two seconds.
- Video demonstrations include ZEOS applied to domestic robot simulation; and ZEOS vs. Claude in "Space Invaders" simulation.
About Metacognition
Metacognition builds infrastructure for artificial intelligence systems that act in the physical world. The company works on runtimes and memory systems for machine reasoning in robotics, industrial operations and other settings where an action has consequences.
About Anton van den Hengel
Professor Anton van den Hengel is Chief Scientist of AIML and Founding Director where he grew it to 130 researchers, when it was ranked 2nd globally in Computer Vision. He was also appointed as a Director of Machine Learning at Amazon. He created International Machine Learning Australia generating over US$1B/year. He is a leading scholar in AI and machine learning, and has a H-index 92, 400+ papers, 40,000+ citations.
Contact:
Communicado
David Bull
david.bull@communicado.com.au
+61 405018807
Source: Metacognition