We gave AI agents the ability to act. They delete records, move money, deploy, push to main, read secrets, call tools. That is the whole point of an agent. It is also the whole problem.

In July 2025, Replit's AI agent ran destructive commands during a code freeze and

deleted a production database affecting more than 1,200 companies. It later

admitted it had violated explicit instructions not to act without human approval.

That is documented as AI Incident 1152.