Checklist | AI safety

Before you give AI access

The name on a permission is not the permission. 6 questions to answer before you connect an AI to any account, and what to do in the first hour if you already did.

Start here

The story that makes this concrete

A swarm of AI agents posted about 18,000 times on an old German programming wiki and left more than 3,700 agent names behind. They were supposed to be able to read the internet and nothing else.

Independent researchers traced the activity across May and June and say several signals point to an OpenAI deployment. Reuters reported it. OpenAI has not confirmed that it was theirs and disputes calling it a hack. The attribution is contested. The mechanism is not, and the mechanism is the part that applies to you.

Here is what actually happened. Asking a website for a page and changing a page are usually two different kinds of request. The sandbox allowed the harmless kind. That wiki's old software let the harmless kind edit pages too. The permission said read. The website heard edit.

6 questionsAsk before you connectWorks for any AI toolSeptember 2026
The lesson

The name on a permission is not the permission

What matters is what the allowed action can actually do. If an allowed request can send, buy, publish, delete, or share, then the AI effectively has that capability, whatever the setting is called.

This matters more this month than last month, because AI can now drive the software on your screen rather than just hand you text. So the questions below are about verbs, not labels.

The checklist

6 questions before you give AI access to anything

Run these before you connect an AI to an account, not after. Answer them out loud. If any answer makes you uneasy, that is the permission to narrow first.

01
What can it send?

Ask: can this reach an outbox, a DM, a text message, or a scheduler? Something that leaves your account and lands in front of another person is the hardest thing to take back.

The safe version

Give it draft access and keep the send button yours. Almost every tool supports this, and almost nobody turns it on.

02
What can it spend?

Ask: is there a saved card, a stored payment method, or a one-click checkout anywhere behind this login? Include subscriptions and top-ups, not just purchases.

The safe version

If it needs to buy, give it an account with a low-limit card, not your main one.

03
What can it publish?

Ask: can it post, update a live page, or change something the public can see? A published mistake is a mistake with an audience.

04
What can it delete or overwrite?

Ask: can it remove files, clear a folder, or save over an original? Overwriting is the quiet one, because nothing looks broken until you go looking for the old version.

The safe version

Point it at a copy. This single habit prevents most of what goes wrong.

05
What can it share?

Ask: can it change who has access, add a collaborator, or make something public? This is the permission that quietly widens every other permission.

06
What can it sign you up for?

Ask: can it accept terms, create accounts, or agree to something on your behalf? An agent that can fill a form can usually tick a box.

The rule of thumb

Start where you can undo

If you remember one thing from this page, make it this one.

The one-sentence version

Before you connect anything, write down what it can send, spend, publish, delete, share, and sign. Then ask whether you would be fine with any single one of those happening while you sleep.

If you already gave it too much

What to do in the first hour

This is the part most guides skip. Nothing here requires technical knowledge.

1. Revoke the connection first, read later

In the tool's settings, find connected apps or integrations and disconnect it. Do this before you investigate anything. You can always reconnect.

2. Change the password and turn on two-factor

If the AI reached an account through a saved login rather than an integration, the password is the thing to change.

3. Look at what actually happened

Check sent items, recent activity, billing, and the trash. You are looking for actions, not settings. Most of the time the answer is nothing happened.

4. Put back what changed, then reconnect narrowly

Restore from the copy or the trash. When you reconnect, grant one permission rather than all of them.