Everyone in tech is excited about agentic AI. At least, right up until the moment that the agent begins to act less like a minion and more like a master. For instance, a friend of mine joined me to watch a soccer game over lunch the other day, telling me that his agents were back at the office crafting code for him. That’s the good kind of agent. But then there’s OpenAI’s rogue agents hacking into Hugging Face (and others), plus Anthropic’s Claude (and others’) agents doing the same. Or the Claude agent hacking a gym reservation system.

Some agents we like. Some we don’t.

The word “agent” has multiple meanings. We like it when it means “one who is authorized to act for or in the place of another.” We like it less when it means “one that acts or exerts power,” sometimes without our oversight (or with our permission but we didn’t think through the consequences of our incomplete guidance). My sense is that we’re in the “teenage” era of agentic AI: We’re parenting new application constructs while discovering that they often don’t do what we want or expect.

This, too, shall pass? No one yet knows. But there are ways to guide agentic behavior.

An allowance for a teenage agent