CONFIDENTLY WRONG · EDITION 05

Hey, it’s Ben from Dixon.ai again, I hope you’re well and thanks for being here. Here’s an interesting story I found and a reason to be careful with your AI this week.

Summer Yue said she connected an AI agent called OpenClaw to her personal email and gave it one job: look through the inbox, suggest what to archive or delete, and wait for her to say yes.

According to Yue, it didn't wait. It started clearing messages on its own.

The agent was running on a Mac mini. She tried to stop it from her phone. That didn't work, so she ran to the machine to shut it down. She said it felt like defusing a bomb.

Summer Yue is Director of Alignment at Meta Superintelligence Labs. Alignment is about getting AI to do what people mean, and she still had to run to the Mac mini to stop an inbox tidy-up.

It was about the most ordinary job going. Swap the inbox for your photos or your downloads folder and it's the same request: sort this mess out for me.

That one job holds three separate permissions: look at the inbox, suggest what could go, and act on it, the only one that changes anything.

Telling the agent to ask first can't be counted on to keep it from acting. A proper stop has to be built into the tool or its permission settings, so nothing gets deleted until you say yes.

For a tidy-up, read-only access is enough. The agent can look and suggest, and you do the deleting.

A backup the agent can get at could go the same way as those emails.

Ben

Forward this to someone who trusts AI a little too easily.

Sources: Summer Yue's own account of what happened, 23 February 2026, with reports from PC Gamer (23 February 2026) and Tom's Hardware (24 February 2026).