The name on a permission is not the permission. 6 questions to answer before you connect an AI to any account, and what to do in the first hour if you already did.
A swarm of AI agents posted about 18,000 times on an old German programming wiki and left more than 3,700 agent names behind. They were supposed to be able to read the internet and nothing else.
Independent researchers traced the activity across May and June and say several signals point to an OpenAI deployment. Reuters reported it. OpenAI has not confirmed that it was theirs and disputes calling it a hack. The attribution is contested. The mechanism is not, and the mechanism is the part that applies to you.
Here is what actually happened. Asking a website for a page and changing a page are usually two different kinds of request. The sandbox allowed the harmless kind. That wiki's old software let the harmless kind edit pages too. The permission said read. The website heard edit.
What matters is what the allowed action can actually do. If an allowed request can send, buy, publish, delete, or share, then the AI effectively has that capability, whatever the setting is called.
This matters more this month than last month, because AI can now drive the software on your screen rather than just hand you text. So the questions below are about verbs, not labels.
Run these before you connect an AI to an account, not after. Answer them out loud. If any answer makes you uneasy, that is the permission to narrow first.
Ask: can this reach an outbox, a DM, a text message, or a scheduler? Something that leaves your account and lands in front of another person is the hardest thing to take back.
Give it draft access and keep the send button yours. Almost every tool supports this, and almost nobody turns it on.
Ask: is there a saved card, a stored payment method, or a one-click checkout anywhere behind this login? Include subscriptions and top-ups, not just purchases.
If it needs to buy, give it an account with a low-limit card, not your main one.
Ask: can it post, update a live page, or change something the public can see? A published mistake is a mistake with an audience.
Ask: can it remove files, clear a folder, or save over an original? Overwriting is the quiet one, because nothing looks broken until you go looking for the old version.
Point it at a copy. This single habit prevents most of what goes wrong.
Ask: can it change who has access, add a collaborator, or make something public? This is the permission that quietly widens every other permission.
Ask: can it accept terms, create accounts, or agree to something on your behalf? An agent that can fill a form can usually tick a box.
If you remember one thing from this page, make it this one.
Before you connect anything, write down what it can send, spend, publish, delete, share, and sign. Then ask whether you would be fine with any single one of those happening while you sleep.
This is the part most guides skip. Nothing here requires technical knowledge.
In the tool's settings, find connected apps or integrations and disconnect it. Do this before you investigate anything. You can always reconnect.
If the AI reached an account through a saved login rather than an integration, the password is the thing to change.
Check sent items, recent activity, billing, and the trash. You are looking for actions, not settings. Most of the time the answer is nothing happened.
Restore from the copy or the trash. When you reconnect, grant one permission rather than all of them.