This is a good analogy and a useful way for Boards to think about risk. That is not the only job for Boards though. Companies need to be experimenting with AI then learning and evolving based on the results. Boards need to help open up this kind of thinking not just point out the risks.
in the now (in)famous PocketOS case it only took 9 seconds for the agent to delete a company’s entire production database and its backups, violating in the process "every principle it was given", like Yul Brynner in Mondwest.
The unglamorous part is the real bottleneck. Live agent inventory, named handlers, least-privilege credentials, immutable logs, etc - none of this is hard to describe. It's hard to prioritise in an organisation that's still excited about what agents can do.
This is a good analogy and a useful way for Boards to think about risk. That is not the only job for Boards though. Companies need to be experimenting with AI then learning and evolving based on the results. Boards need to help open up this kind of thinking not just point out the risks.
Absolutely right @Kenny Fraser. Board need to both encourage adoption whilst managing the risk. Not an easy task
Agreed!
in the now (in)famous PocketOS case it only took 9 seconds for the agent to delete a company’s entire production database and its backups, violating in the process "every principle it was given", like Yul Brynner in Mondwest.
(https://www.theguardian.com/technology/2026/apr/29/claude-ai-deletes-firm-database)
💯
And continuous monitoring of latest security loopholes on the open market + penetration testing for live agents
Good add Manu
The unglamorous part is the real bottleneck. Live agent inventory, named handlers, least-privilege credentials, immutable logs, etc - none of this is hard to describe. It's hard to prioritise in an organisation that's still excited about what agents can do.
Absolutely - and the tools to implement these controls are still immature