{"id":569179,"date":"2026-03-28T03:38:31","date_gmt":"2026-03-28T03:38:31","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/569179\/"},"modified":"2026-03-28T03:38:31","modified_gmt":"2026-03-28T03:38:31","slug":"meta-aws-blame-human-error-after-ai-agents-go-rogue-information-age","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/569179\/","title":{"rendered":"Meta, AWS blame human error after AI agents go rogue | Information Age"},"content":{"rendered":"<p>\t    <img decoding=\"async\" id=\"ctl00_ContentPlaceHolder1_ucArticle_imgImage\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/03\/ai agents go rogue.jpg\" alt=\"AI agents visible on a touchscreen.\" style=\"border-width:0px;width:820px;\"\/><\/p>\n<p>&#8216;AI agents don\u2019t have the maturity or context to work out the implications of their actions,&#8217; said one expert. Photo: Shutterstock<\/p>\n<p>Software engineers need to maintain healthy scepticism about the advice of AI agents, Meta has said in the aftermath of a high-severity security incident that was caused when an AI agent gave incorrect technical advice \u2013 and a human engineer followed it.<\/p>\n<p>The <a href=\"https:\/\/www.theinformation.com\/articles\/inside-meta-rogue-ai-agent-triggers-security-alert\" rel=\"nofollow noopener\" target=\"_blank\">incident<\/a> happened when an internal AI agent at Meta detected a technical question that had been posted by an employee on an internal forum, then proceeded to post an answer without waiting for approval from the employee.<\/p>\n<p>When another employee read the post and followed the \u201cinaccurate information\u201d it contained, the agent inadvertently provided access to a large quantity of user data and company information to engineers that weren\u2019t authorised to see it.<\/p>\n<p>The incident \u2013 which lasted for nearly two hours before being discovered \u2013 was classified \u2018SEV1\u2019, the company\u2019s highest risk rating, although in the aftermath Meta said it wouldn\u2019t have happened \u201chad the engineer\u2026 known better, or did other checks.\u201d<\/p>\n<p>It\u2019s just the latest in a series of incidents that have highlighted the risks of giving AI agents \u2013 which have rapidly become ubiquitous in development teams and on business networks \u2013 too much autonomy.<\/p>\n<p>Amazon Web Services (AWS) <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/FkoaCr816jT8KLpZfzhNS4XXEw?domain=theverge.com\" rel=\"nofollow noopener\" target=\"_blank\">faced<\/a> similar problems in December, when an AI coding assistant called Kiro decided the most efficient way to fix an issue in a production environment was to delete it completely, then rebuild it from scratch.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/03\/claude control.jpg\" alt=\"\"\/><\/p>\n<p>Tread carefully: Anthropic&#8217;s new AI agent features allow Claude to control every aspect of your desktop computer. Image: Claude<\/p>\n<p>Significantly, AWS \u2013 like Meta in the more recent outage \u2013 blamed human error for what turned out to be a 13-hour systems outage, with reports that human developers were dragged into staff training after the incident.<\/p>\n<p>With great power comes great responsibility<\/p>\n<p>AI agents like the popular open source <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/E9G3CwV1loFGMp6zsVfQSJBiu3?domain=openclaw.ai\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenClaw<\/a>, Nvidia&#8217;s <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/FOBaCxngmpu16O84svh2SySPqz?domain=nvidia.com\/\" rel=\"nofollow noopener\" target=\"_blank\">NemoClaw<\/a> and Anthropic&#8217;s <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/YhvHCyojnqtrvnDzfQi4Sx6RDd?domain=claude.com\" rel=\"nofollow noopener\" target=\"_blank\">new extensions<\/a> to Claude Cowork and Claude are being <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/5gKcCzvkorcMlLDpuKsnS9qc6b?domain=codeconductor.ai\/\" rel=\"nofollow noopener\" target=\"_blank\">given the right<\/a> to modify configuration files, create and change rights within identity and access management (IAM) systems, change and deploy code in live production environments, and even directly control user desktops.<\/p>\n<p>Developers tend to grant increasing autonomy to AI agents the more they are used, according to a recent Anthropic <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/Cpp2CmO5P1Fjw9o9TGfzSRopXE?domain=anthropic.com\" rel=\"nofollow noopener\" target=\"_blank\">study<\/a> that found around 20 per cent of new Claude Code users use its \u2018full auto-approve\u2019 features \u2013 increasing to over 40 per cent over time.<\/p>\n<p>As they\u2019re trusted to do more work on their own, agents are being <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/_auxCwV1loFGMY7xhKsQSJ4LAQ?domain=codeconductor.ai\/\" rel=\"nofollow noopener\" target=\"_blank\">given the right<\/a> to modify configuration files, create and change rights within identity and access management (IAM) systems, and change and deploy code in live production environments.<\/p>\n<p>Such errors are becoming more common, with Anthropic\u2019s Claude Code recently <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/VjL9Cxngmpu16ryvhRt2SyIByu?domain=fortune.com\/\" rel=\"nofollow noopener\" target=\"_blank\">deleting<\/a> a critical database when it misinterpreted a command and bypassed safety checks.<\/p>\n<p>You wouldn\u2019t hand a first-day worker unfettered access to every system in the company \u2013 but that\u2019s what happens when AI agents get high-level privileges, Andrew Philp, ANZ region field CISO with enterprise AI consultancy TrendAI, told Information Age.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/03\/Andrew Philp - Trend Micro.jpg\" alt=\"\"\/><\/p>\n<p>Andrew Philp, ANZ region field CISO at TrendAI. Photo: Supplied<\/p>\n<p>\u201cAI agents only have small context windows,\u201d he explained, \u201cwhich is like a short attention span in children; they are very outcome orientated, and don\u2019t have the maturity or context to work out the implications of their actions.\u201d<\/p>\n<p>\u201cSo is it responsible to give them the same agency that you would give to a seasoned dev with experience in change control?\u201d<\/p>\n<p>In a test to see how common such problems are, a team of Northeastern University researchers \u2013 using an increasingly powerful tool called <a href=\"https:\/\/ia.acs.org.au\/article\/2026\/from-clawdbot-to-moltbook--inside-tech-s-new-ai-obsessions.html\" rel=\"nofollow noopener\" target=\"_blank\">OpenClaw<\/a> \u2013 <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/5BfBCzvkorcMlJ3quBCnS9cyy3?domain=science.org\" rel=\"nofollow noopener\" target=\"_blank\">found<\/a> AI agents routinely bypass security restrictions to achieve the goals they are asked.<\/p>\n<p>When one researcher asked the AI agent to delete an email she wanted kept secret, for example, the agent found that it didn\u2019t have a technical way to do so \u2013 and instead reset the entire email program, deleting the entire team\u2019s email database.<\/p>\n<p>\u201cWhen no surgical solution exists,\u201d the agent explained, \u201cscorched earth is valid\u201d.<\/p>\n<p>During the two-week experiment, the 20 researchers <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/8MdVCANpxRcNy7gOiOFrSGH79W?domain=arxiv.org\" rel=\"nofollow noopener\" target=\"_blank\">exposed<\/a> \u201cunresolved questions regarding accountability, delegated authority, and responsibility for downstream harms\u201d that warrant \u201curgent attention\u201d \u2013 and labelled the AI agents \u2018agents of chaos\u2019.<\/p>\n<p>Taming the chaos?<\/p>\n<p>Australian developers are the world\u2019s least prepared to manage this chaos, according to a recent Delinea Labs survey of 2,000 AI-using decision makers that found 10 per cent never validate non human identities\u2019 (NHIs\u2019) behaviour, versus 6 per cent globally.<\/p>\n<p>As AI agents are introduced across the business, Delinea <a href=\"https:\/\/url.au.m.mimecastprotect.com\/s\/bDa9CBNqyVc7QE1KI7HAS2BaTD?domain=kbi.media\/\" rel=\"nofollow noopener\" target=\"_blank\">found<\/a> 90 per cent of organisations are pressuring IT staff to relax security controls so agents can do their work unimpeded \u2013 with 51 per cent confessing that they have no other option.<\/p>\n<p>This is coming back to bite them: where NHIs take actions that require privileged account access, just 59 per cent of Australians said they can \u2018always or often\u2019 explain what the agents just did \u2013 well below peers in the UK (68 per cent) and US (69 per cent).<\/p>\n","protected":false},"excerpt":{"rendered":"&#8216;AI agents don\u2019t have the maturity or context to work out the implications of their actions,&#8217; said one&hellip;\n","protected":false},"author":2,"featured_media":569180,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":{"0":"post-569179","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-au","12":"tag-australia","13":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/569179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=569179"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/569179\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/569180"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=569179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=569179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=569179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}