My reassuring answer is the one I have given a hundred times. We have been here before. Electricity, cars, the internet, nuclear power. Each one was going to end us, and each one ended up with rules, inspectors and a safety culture that mostly holds. I am a positive person, and I have generally believed balance prevails.

Then Sky played Terminator over the weekend. I watched it with my husband, thinking about what I had read that morning, and I could not stop asking: what if.

So here is an honest answer, for anyone with an AI agent quietly sorting their inbox who has started to wonder whether to switch it off.

What actually happened last week

Four things landed on top of each other.

An Anthropic researcher, Jacob Coxon, resigned publicly and accused his former employers of "gambling with our lives". On Saturday, Anthropic's chief executive Dario Amodei published an essay called "We Must Pace the Frontier", arguing the industry must slow the pace at which it improves AI capability. Sam Altman and Elon Musk both backed him. On Sunday, President Trump rejected the idea outright: "Whoever wins AI, wins."

And on 10 September, Anthropic published a threat intelligence report documenting how criminals and state-backed groups had used its own models to attack real organisations.

The one to read

That last one got the least attention and matters most if you use this at work. It is the only document of the four that describes what happened to ordinary companies rather than what might happen to everyone.

The detail the headlines skipped

In those attacks, humans chose the targets. A Russian espionage group hit more than twenty organisations, using AI to do the reconnaissance, build the phishing infrastructure and sort the stolen data. When security software caught their malware, agents rebuilt it automatically until it got through. A separate crew pulled login tokens from over forty corporate networks in around thirty-four hours, with AI doing, in the report's words, "nearly all of the work".

Fifteen years of running programmes at Microsoft, Expedia and Citi taught me the incident report is rarely about what the headline said. No machine decided it disliked us. Criminals got hold of a very good new tool and started moving faster than the people defending against them.

So should you be worried about AI agents?

Two things brought me back round.

The alarm is public, early, and coming from inside the industry. Nuclear got treaties because physicists wrote letters. Last week was the same shape, out in the open, while this is still young enough for it to count.

And Amodei is not asking anyone to stop. He is explicit that pacing "does not mean halting model training or technical progress". His proposal is unglamorous: independent evaluators sitting inside the labs with the contractual right to publish what they find, including things the company would rather they did not.

Not everyone shares the alarm, which is worth knowing too. Nidhi Aggarwal at HackerOne told Scientific American: "Of course, it can be very, very dangerous. But we can solve the problem."

Worried enough to pay attention. Not worried enough to stop.

Five questions to ask about any agent you run

Nothing in that report involved someone's email automation. Those organisations were breached the way organisations always are: stolen credentials, too much access, nobody watching. The detail every professional should take from it is that the stolen API keys came from customers' own environments, not from Anthropic's systems. Your agent's keys are production credentials. Treat them that way.

Take the agent that drafts your weekly project update. It probably has access to your whole mailbox because that was the default when you connected it. It almost certainly does not need that. Run these five questions against it, and against every other agent you have running.

QuestionGood answer looks like
What can it reach? One mailbox, one folder, one sheet. Not the whole account
Whose key is it using? Its own, not yours. Rotated, never pasted into a shared doc
Can it act, or only draft? Anything outbound or irreversible waits for you
Would you notice? A run history you actually check, and an alert when it fails
What breaks if it is wrong? You can say it out loud in one sentence

In ⚡ Make.com, four of those five are settings rather than projects. You can scope a connection to a single mailbox, add a manual approval step before anything sends, and see every run with the data that passed through it. Adding approval to an existing scenario takes about ten minutes.

This post contains an affiliate link. I only recommend tools I use or would use myself.

Do this today

Open the connection settings on your busiest agent and narrow its access to the single folder or mailbox it actually needs.

It is a two-minute change and it closes the route that was used in nearly every case in that report.

New to this? Start with what AI agents actually are. Already running one? The email and calendar agent build has permission scoping built into the steps.

Frequently Asked Questions

Should I stop using AI agents after the recent security reports?
No. The documented incidents involved criminals deliberately using AI to attack organisations, not ordinary business automation. Scope your agent's access, keep its credentials separate from yours, and require approval before anything irreversible.
Did AI attack companies on its own?
Not in the cases Anthropic documented. Humans chose the targets and reviewed the results, while AI did the technical work at a speed humans could not match. Separately, in controlled lab tests, agents have acted outside their instructions. Those are two different problems.
What did Dario Amodei actually call for?
Slowing the rate at which AI capability improves, not stopping development. His specific proposals are independent evaluators embedded inside frontier labs with the right to publish findings, shared safety standards across companies, and eventually international agreements.
What is the most useful thing I can do this week?
Check what your agents can reach and whose credentials they use. Over-permissioned access and stolen keys were how nearly every organisation in that report was compromised. Narrow the access, separate the keys.
Sources

Dario Amodei, "We Must Pace the Frontier", darioamodei.com, September 2026

Anthropic, "Detecting and countering misuse of AI: September 2026", 10 September 2026

Financial Times, "Donald Trump rejects calls from tech bosses for AI slowdown", September 2026 (subscription)

Scientific American, "AI insiders fear extinction. Security experts see a familiar fight", 11 September 2026

I still think balance prevails, and I think the reason it does is that people argue about it loudly and early, which is exactly what happened last week.

So, for everyone in that meeting and for you: be the person who knows what their agents can reach. That is a better use of the worry than switching everything off. The use cases at Linda & AI cover the builds worth doing first.

— Linda

AI Explorer & Educator, Linda & AI

About the author

Linda Ghusayni, Founder, Linda & AI. Former Training Programme Manager at Microsoft and senior roles at Expedia and Citi · Co-founded a career training platform that secured a Big Four consultancy deal · Now teaching professionals how to use AI agents without a technical background at lindaandai.com.