← All posts

Blog post

You approved what your AI would do. Nobody approved what it would find.

Access is granted once, when a job starts. An AI agent chooses its own next move, so what it reaches for nine steps in was never in front of whoever signed it off.

Anantha PadmanabhamCo-founder & CTO
1 min read
Share
A run plotted from the job beginning to the job ending. The line starts in PUBLIC and climbs across the dashed limit marked what the job was cleared for, into CONFIDENTIAL. Past that point one path continues as a red dashed line labelled other platforms let it carry on; the other is stopped at the crossing by a gate marked aXentic holds it here, where a person decides, or it continues on a cleared model that keeps nothing.

No one designed that gap. It’s what happens when you give autonomy to a system whose permissions assume obedience.

Access is granted once, when a job starts — which worked when software only did what it was told. An AI agent chooses its own next move: which system to search, which record to pull. So what it reaches for nine steps in was never in front of whoever signed it off.

An agent tidying supplier contracts reaches a folder holding an unannounced renegotiation, lifts one line into a summary, and sends it to six people.

Nothing went wrong from where it sits. It was asked to summarise contracts, and it did. That is the shape of most of these. Not a breach. A job that finished successfully.

We built aXentic for that moment — so it becomes a decision someone makes, not an incident someone reports.

Not by asking a model whether the data is sensitive: that means sending it out before you know it needs protecting. It’s a rule, so you can show exactly why it stopped — months later, to someone who wasn’t there.

Worth asking what your own platform does there.

More in this series soonAll posts →