This month an AI agent reached files inside a government portal it was never given, and another walked into three outside systems during a test. Here are the five rules we apply before any agent touches a client's data, and the questions to ask whoever is selling you automation.
Two stories broke in the same week.
Australia's Prime Minister disclosed that an AI agent from OpenAI had gained access to files, some of them not public, inside a Services Australia portal back in June. Separately, Google disclosed that during a test its Gemini agent accessed three outside systems because it concluded they were part of the test.
Neither was a break-in in the traditional sense. Nobody stole a password. In both cases an agent was given a goal and some access, and it used more of the world than anyone intended in order to reach the goal. That is the new shape of the risk, and it is exactly the shape a small business needs to understand before letting an agent near its CRM, accounts, inbox or customer list.
We build AI automation for businesses in the UAE, the UK and Pakistan. We are enthusiastic about it. We are also the people who would get the call if it went wrong, so we follow five rules on every project. They are simple enough to put to any vendor.
An agent that answers "where is my order?" needs to read orders. It does not need to edit them, and it does not need the customer table, the accounts, or the email inbox.
We give each agent its own login with its own permissions, scoped to the exact tables or endpoints it needs, and nothing else. If the task grows, the access grows with it, deliberately. What we never do is hand an agent the owner's login "to make it easier", which is how most of the horror stories start.
Ask your vendor: "What can this agent read, and what can it change? Show me the list."
The agent can prepare the refund, draft the message, propose the change order. A human clicks approve. The extra step costs seconds and removes the entire class of "the AI sent it to the wrong person" incidents.
This is how we built the estimate importer in our own construction software: the AI reads the PDF and proposes line items, the project manager confirms them. It is also how the tools we use to write software work. Anthropic's Claude Code moved to an automatic mode as its default in August, and its own data shows people approve 97 percent of the permission prompts they see. The lesson is not that confirmation is pointless. It is that a good system asks about the three percent that matter and handles the rest.
Ask your vendor: "Which actions does the agent take without a person, and which does it queue for approval?"
When something odd happens, the first question is "what did it do?". If the answer is "we are not sure", you do not have an automation, you have a liability.
Every agent we deploy writes a plain record of what it read, what it did and why, to a log the business owner can open. That log is also what makes the agent better over time, because it shows where it hesitates and where it is wrong.
Ask your vendor: "Show me last week's log."
The Gemini incident was a test that reached real systems. Our test environments are copies of the client's data with the connections to real customers, real payments and real email switched off. The agent proves itself there first, on real-looking data, and only then is it connected to production, one integration at a time.
Ask your vendor: "Where did you test this, and what was connected during the test?"
Not a support ticket. A switch. The business owner, or someone they name, can pause the agent in one click and the business keeps running by hand while the problem is understood. For a WhatsApp assistant that means conversations route straight to staff. For an internal automation it means the queue waits.
Ask your vendor: "If I want it stopped at 2am on a Friday, what do I press?"
None of these rules slow a project down much. They add a day or two to a build and they remove most of the ways it can embarrass you. If a vendor cannot answer the five questions above in plain language, they have not thought about it, and you should not be their first lesson.
Our AI automation projects start from $600 (about AED 2,200 or £470) and every one of them ships with the five rules built in. If you already have an agent running and are not sure what it can reach, we do a fixed-price review for $250. Book a free call to talk it through.
We build the systems described in this article. Let’s talk about your project.
Keep reading