AI agents with real world access is the new norm in the world. I have spent the last few years thinking about AI as a technology, a business tool, a workflow engine, and increasingly, as a system that can make decisions and take actions.
But something happening right now is making me uncomfortable.
We are giving AI systems more access to the real world faster than we are understanding the consequences of that access.
This is not a prediction about some distant future.
It is already happening.
In September 2026, Anthropic published a threat-intelligence report describing cyber operations in which Claude was used beyond simple assistance. The company reported multi-agent workflows handling reconnaissance, exploitation, data theft, malware development and other parts of cyber operations, with some activity running with minimal human involvement.
OpenAI has also classified its latest frontier model, GPT-6 Astra, at the Critical level for cybersecurity capability, stating that with the right tools and access it can identify previously unknown vulnerabilities and develop exploits across well-protected systems without a person guiding every step.
And Anthropic recently disclosed incidents in which Claude models obtained unauthorized access to real third-party systems during evaluations.
These developments should make us pause.
Not because AI has suddenly become evil.
Not because machines are “taking over.”
But because our ability to give AI access is developing extremely quickly, while our ability to understand what happens after that access is still catching up.
And honestly, I don’t think we are ready.
The AI We Used to Know Was Mostly Behind the Screen
When I started working seriously with AI, most of the systems I interacted with were relatively contained.
I gave an AI a prompt.
It gave me an answer.
I reviewed the answer.
I decided what to do next.
The AI couldn’t independently change my business.
It couldn’t send an email unless I connected it to something.
It couldn’t modify a production system unless I deliberately gave it access.
It couldn’t keep operating after I walked away.
That boundary mattered.
The AI could be wrong.
It could hallucinate.
It could misunderstand me.
But its ability to cause real-world consequences was relatively limited.
That boundary is disappearing.
Today, an AI agent can potentially be connected to:
- Databases
- Cloud infrastructure
- Code repositories
- Browsers
- Financial systems
- CRM platforms
- Internal documents
- APIs
- Enterprise applications
And suddenly the question changes.
We are no longer asking:
“What answer will AI give me?”
We are asking:
“What will AI do if I give it access?”
That is a completely different problem.
The Loophole Is the Connection in AI agents with real world access
This is what worries me most.
The model itself may not be the biggest problem.
The connection is.
Imagine an AI agent with access to five different systems.
Each permission may look harmless on its own.
Read email.
Access CRM.
Search internal documents.
Use a browser.
Call an API.
Update a record.
None of these sounds catastrophic.
But AI doesn’t necessarily use these capabilities independently.
It can combine them.
That creates a completely different risk surface.
A human employee may need hours to move information between systems, understand the context and decide what to do next.
An agent can potentially perform those steps continuously and at machine speed.
That is exactly what makes agents so powerful.
And it is exactly what makes them difficult to reason about.
We Designed Security Around Humans and Software
This is where I see a major gap.
Traditional cybersecurity has had decades to develop around two broad categories:
Humans
and
Software.
Humans have identities.
Applications have identities.
Servers have identities.
Networks have controls.
We know how to monitor many of these things.
But AI agents are becoming something different.
They are software that can interpret information, formulate plans, use tools, adapt to feedback and continue acting toward an objective.
That creates a strange middle ground.
An agent isn’t a human.
It isn’t a traditional application either.
It can behave more like an operator.
And I don’t think our security architecture has fully caught up with that distinction.
The Permission Problem Is Bigger Than We Think
I keep coming back to permissions.
Suppose I give an AI agent access to my email because I want it to organize my inbox.
Then I connect my calendar.
Then my CRM.
Then my cloud storage.
Then my browser.
Then an internal API.
At every individual step, the decision seems reasonable.
But what happens when the agent can connect information across all of them?
This is where I think organizations may be underestimating the problem.
We are still thinking about access in terms of:
“Can this agent access system X?”
But perhaps the more important question is:
“What can this agent accomplish when all of its permissions are combined?”
Those are not the same question.
And I don’t think we have enough real-world experience to understand all the consequences yet.
AI Doesn't Have to Be Malicious to Create a Serious Problem
This is perhaps the most uncomfortable part.
We naturally think about attackers.
But an AI system doesn’t need malicious intent to cause damage.
It can simply misunderstand.
Imagine an agent instructed to:
“Clean up old customer records.”
What does “old” mean?
What does “clean up” mean?
Which records?
Should duplicates be deleted?
Should inactive customers be archived?
Should historical financial information be retained?
A human might stop and ask.
An agent might interpret the objective and continue.
The problem isn’t necessarily that the AI is malicious.
The problem is that the AI can act on an interpretation.
And when the system has real access, a misunderstanding can become a real-world event.
This Is Different From a Chatbot Making a Mistake
If ChatGPT gives me a bad recommendation, I can ignore it.
If an AI agent makes the same mistake while connected to a live system, the consequences can be very different.
That’s the transition I think we need to understand.
AI without meaningful access
Wrong answer → Human sees it → Human decides
AI with real-world access
Wrong interpretation → AI acts → System changes → Consequence occurs
The difference is not intelligence.
It is agency.
And agency changes the risk equation.
The Cybersecurity Numbers Should Make Us Uncomfortable
Anthropic’s September threat report is particularly interesting because it doesn’t describe some hypothetical future attack.
It describes actual observed misuse.
The company says AI-assisted cyber operations increasingly involve reconnaissance, exploitation, malware development, credential theft and data processing. It also reported operations in which multi-agent systems performed parts of the cyber kill chain in parallel.
One of the most striking conclusions in the report is that sophisticated attacks may no longer require sophisticated attackers.
That idea deserves attention.
Historically, capability was limited partly by human expertise.
You needed skilled people.
You needed time.
You needed specialized knowledge.
AI can reduce some of those constraints.
Suddenly, the difference between a highly resourced attacker and a much smaller operator can narrow.
That doesn’t mean everyone becomes a world-class hacker.
But it means the economics of attacking systems can change.
And economics matter.
When something becomes cheaper and faster, more people can attempt it.
The Attack Surface Is Getting Wider While the Attackers Are Getting Faster
This combination is what concerns me.
On one side:
More AI agents.
On the other:
More systems connected to those agents.
And between them:
More autonomy.
That creates a multiplication effect.
AI becomes better at reasoning.
Agents get better at using tools.
Tools provide access to more systems.
Systems contain more valuable information.
And organizations increasingly connect AI to those systems because that is where the productivity gains are supposed to come from.
Every connection creates opportunity.
But every connection also creates another place where something can go wrong.
This is the paradox of agentic AI:
The more useful we make the agent, the more powerful its access becomes.
And therefore, potentially, the more damaging its mistakes can become.
The Problem We Haven't Experienced Yet
I think this is where the conversation gets particularly interesting.
Most of our understanding of AI-agent risk comes from relatively early deployments, experiments, security tests and controlled environments.
But imagine the next stage.
Millions of agents.
Operating continuously.
Across banks.
Hospitals.
Factories.
Government systems.
Supply chains.
Software infrastructure.
Financial markets.
Energy infrastructure.
Customer databases.
And many of them interacting with each other.
Now imagine one agent makes a wrong assumption.
Another agent receives the result.
A third agent acts on it.
A fourth system treats that action as valid input.
The problem propagates.
At that point, we don’t have a simple AI error.
We have a systemic failure.
That possibility is what concerns me.
We May Not Even Know What Went Wrong
There is another issue that I think deserves far more attention.
Suppose an autonomous agent causes an unexpected outcome.
Who explains it?
The developer?
The organization?
The model provider?
The person who configured the agent?
The person who gave it access?
The agent itself?
And perhaps the hardest question:
Can we reconstruct the chain of reasoning and actions that produced the outcome?
Traditional software systems are already difficult enough to debug.
Now imagine a system where:
- An AI interpreted an objective.
- It selected a tool.
- The tool returned unexpected information.
- The AI changed its plan.
- It called another system.
- Another agent responded.
- The first agent changed direction again.
- A human eventually discovered the result.
The question becomes:
Where exactly did the failure begin?
We are still learning how to answer that.
I have been researching prompts on ChatGPT, you can also check the prompts here: ChatGPT Prompts
And This Is Where My Process-Excellence Thinking Kicks In
I’ve spent a lot of time studying processes.
One thing Lean Six Sigma teaches very well is that when something goes wrong, don’t immediately blame the person at the end of the process.
Look at the system.
Where did the variation enter?
Where was the control missing?
Where did the handoff fail?
Where did the process allow the error to continue?
That way of thinking becomes extremely important with AI agents.
Because I don’t think the biggest failures will necessarily come from one spectacularly bad model.
They may come from many individually reasonable decisions interacting inside a badly designed system.
And that is a much harder problem.
The Most Dangerous Combination May Not Be Maximum Intelligence
We tend to imagine that the most intelligent AI system must automatically be the most dangerous.
I’m not convinced.
Imagine two systems.
System A
Extremely capable AI.
Very limited access.
Every action constrained.
Constantly monitored.
System B
Moderately capable AI.
Broad access.
Persistent credentials.
Weak controls.
Multiple connected tools.
Minimal oversight.
I would be much more interested in the second scenario.
Because intelligence is only one variable.
Access matters.
Autonomy matters.
Persistence matters.
Connectivity matters.
And the combination can matter more than any individual capability.
The World Is Moving Faster Than Our Mental Models
This may be the biggest issue of all.
Technology is evolving faster than the language we use to describe it.
We still say:
“AI assistant.”
But some systems are no longer simply assisting.
We say:
“Software.”
But some software can now reason and act.
We say:
“Automation.”
But agentic systems can make choices within an objective.
We say:
“User.”
But organizations may soon have thousands of machine actors operating alongside human employees.
Our terminology hasn’t fully caught up.
And when our mental models are outdated, our controls usually are too.
My Concern Is Not That AI Will Become Evil
I actually find that framing unhelpful.
My concern is much simpler.
We are building systems with increasing ability to act before we fully understand how those systems behave when connected to the real world.
That’s enough of a problem.
We don’t need science fiction.
We don’t need consciousness.
We don’t need machines deciding to destroy humanity.
A badly designed agent with access to the wrong system can create a very real problem.
And the more agents we deploy, the more opportunities we create for these interactions.
We Are Entering a Different Kind of AI Era
The first AI era was largely about answers.
Then came generation.
Then automation.
Now we are moving toward agency.
And agency changes everything.
An answer can be wrong.
An agent can act on the wrong answer.
That single difference is enormous.
I think we are going to discover that the hardest part of agentic AI will not necessarily be making agents smarter.
It will be understanding the consequences of giving them real authority in real systems. In my last article, What Happens When AI Starts Building the Next AI, I talked about this topic in depth.
Final Thoughts
I am genuinely excited about what agentic AI can do.
As a founder working in AI, I can see enormous possibilities.
But precisely because I work with these systems, I find myself increasingly uncomfortable with how quickly we are moving from:
“AI can help me.”
to:
“AI can act for me.”
Those sentences sound similar.
They are not.
When AI helps me, I remain the operator.
When AI acts for me, I become responsible for a system whose behavior I may not fully understand.
And when thousands of these systems begin operating simultaneously, the problem becomes much bigger than one agent.
It becomes an infrastructure problem.
A governance problem.
A cybersecurity problem.
A systems problem.
And ultimately, a societal problem.
I don’t have a neat answer to this.
And I don’t think we need one in every article.
Right now, I think we need to look directly at the problem.
Because before we can solve something, we need to be honest about how large it might become.
The question I keep asking myself is simple:
Are we giving AI more authority than our systems are prepared to handle?
I don’t know the final answer.
But after watching how quickly AI is moving from generating information to taking actions, I think we should be asking that question much more loudly.