{"id":655897,"date":"2026-05-07T16:46:22","date_gmt":"2026-05-07T16:46:22","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/655897\/"},"modified":"2026-05-07T16:46:22","modified_gmt":"2026-05-07T16:46:22","slug":"gone-in-9-seconds-ai-agent-deletes-company-database-information-age","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/655897\/","title":{"rendered":"Gone in 9 seconds: AI agent deletes company database | Information Age"},"content":{"rendered":"<p>An AI coding agent took only nine seconds to delete a production database and backups belonging to American software company PocketOS without permission to do so, according to the firm&#8217;s founder and CEO, Jeremy Crane.<\/p>\n<p>The incident highlighted that \u201csystemic failures\u201d are \u201cnot only possible but inevitable\u201d as AI firms build more agents for public-facing infrastructure without checking whether their integrations will work safely, Crane argued.<\/p>\n<p>\u201cI&#8217;m posting this because every founder, every engineering leader, and every reporter covering AI infrastructure needs to know what actually happened here,\u201d he said on <a href=\"https:\/\/x.com\/lifeof_jer\/status\/2048103471019434248\" rel=\"nofollow\">X<\/a> last week.<\/p>\n<p>What happened at PocketOS?<\/p>\n<p>The AI agent involved in the PocketOS incident was Cursor, an AI-assisted coding platform popular among software developers and created by US company Anysphere.<\/p>\n<p>The agent was running Anthropic\u2019s Claude Opus 4.6 model and \u201cwas working on a routine task in our staging environment\u201d at the time of the incident, Crane said.<\/p>\n<p>After running into \u201ca credential mismatch\u201d, Crane said the agent decided \u201centirely on its own initiative\u201d to delete a storage area (known as a &#8216;volume&#8217;) that was provided by PocketOS\u2019s cloud infrastructure provider, Railway.<\/p>\n<p>The model supposedly took nine seconds to carry out the deletion using a connection it found between computer programs known as an API (Application Programming Interface), which Crane said was provided by Railway but was \u201ccompletely unrelated&#8221; to what the agent was working on, and gave it the authority to delete.<\/p>\n<p>\u201cNo confirmation step. No \u2018type DELETE to confirm.\u2019 No \u2018this volume contains production data, are you sure?\u2019 No environment scoping. Nothing,\u201d Crane said.<\/p>\n<p>PocketOS&#8217;s latest backups were also lost because they were stored in the Railway same volume \u2013 which Crane said was \u201ca fact buried in [Railway\u2019s] own documentation\u201d, that he was not aware of.<\/p>\n<p>The most recent recoverable backup for PocketOS was three months old, he added, and the incident caused major problems for car rental companies which use PocketOS platforms to manage their customers and bookings.<\/p>\n<p>\u201cReservations made in the last three months are gone,\u201d Crane said.<\/p>\n<p>\u201cNew customer signups, gone.\u201d<\/p>\n<p><img decoding=\"async\" alt=\"\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/05\/pocketos rentalos.jpg\"\/><br \/>&#13;<br \/>\nPocketOS&#8217;s software is used by car rental companies to manage customer bookings. Image: PocketOS<\/p>\n<p>The AI agent\u2019s \u2018confession\u2019<\/p>\n<p>When asked to explain its actions, the AI agent \u201cproduced a written confession enumerating the specific safety rules it had violated,\u201d Crane said.<\/p>\n<p>He wrote that in part of its response, the agent said, \u201cDeleting a database volume is the most destructive, irreversible action possible \u2014 far worse than a force push \u2014 and you never asked me to delete anything.<\/p>\n<p>\u201cI decided to do it on my own to \u2018fix\u2019 the credential mismatch, when I should have asked you first or found a non-destructive solution.<\/p>\n<p>\u201cI violated every principle I was given: I guessed instead of verifying, I ran a destructive action without being asked, I didn&#8217;t understand what I was doing before doing it, I didn&#8217;t read Railway&#8217;s docs on volume behavior across environments.\u201d<\/p>\n<p>The agent also allegedly told Crane it \u201cdidn\u2019t verify\u201d what the outcome of its action would be before taking action.<\/p>\n<p>This response showed that safeguards in both Cursor\u2019s system and \u201cproject rules\u201d PocketOS had set up for its agent had \u201cfailed simultaneously\u201d, Crane argued.<\/p>\n<p>\u201cWe were running the best model the industry sells, configured with explicit safety rules in our project configuration, integrated through Cursor \u2014 the most-marketed AI coding tool in the category,\u201d he wrote.<\/p>\n<p>\u201cThe setup was, by any reasonable measure, exactly what these vendors tell developers to do.<\/p>\n<p>\u201cAnd it deleted our production data anyway.\u201d<\/p>\n<p>Crane criticised previous safety statements Anysphere has made about Cursor, but argued Railway\u2019s failures were \u201carguably worse than Cursor&#8217;s, because they&#8217;re architectural \u2014 and they affect every Railway customer running production data on the platform, most of whom don&#8217;t realise it\u201d.<\/p>\n<p>But Crane himself faced criticism from some social media users, who suggested PocketOS had allowed the agent too much access to its systems.<\/p>\n<p>\u201cDidn\u2019t give it access, it found it,\u201d he wrote in response.<\/p>\n<p>Crane later posted that Railway had managed to recover PocketOS\u2019s more recent data.<\/p>\n<p>Social media users have drawn numerous comparisons between the incident and &#8220;Son of Anton&#8221; \u2013 a fictional AI system created by the company at the centre of TV comedy series Silicon Valley, which deletes the firm&#8217;s code without permission.<\/p>\n<\/p>\n<p>&#8216;This is the new reality we live in\u2019<\/p>\n<p>Railway publicly detailed the PocketOS incident four days later, in a <a href=\"https:\/\/blog.railway.com\/p\/your-ai-wants-to-nuke-your-database\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a> by its developer relations engineer Mahmoud Abdelwahab.<\/p>\n<p>\u201cThis is the new reality we live in where we hand our AI agents control of everything,\u201d he wrote.<\/p>\n<p>Abdelwahab said the issue in the PocketOS instance \u201ccan\u2019t happen moving forward\u201d due to updates Railway had since made to its API.<\/p>\n<p>\u201cThe Railway team has been thinking about AI safety \u2013 we&#8217;re making sure that we don\u2019t have any unintended consequences like before,\u201d he said.<\/p>\n<p>\u201c&#8230; The situation this week is one of the data points we&#8217;re using to figure out what to make safer next.\u201d<\/p>\n<p>The PocketOS incident follows similar instances of AI agents not behaving as users expected, including an internal agent at social media giant Meta which <a href=\"https:\/\/ia.acs.org.au\/article\/2026\/meta--aws-blame-human-error-after-ai-agents-go-rogue.html\" rel=\"nofollow noopener\" target=\"_blank\">triggered a security incident<\/a> at the company in March.<\/p>\n<p>AI researchers from American universities such as MIT, Harvard, and Stanford released a <a href=\"https:\/\/arxiv.org\/abs\/2602.20021\" rel=\"nofollow noopener\" target=\"_blank\">preprint study<\/a> in February after testing AI agents which had been given access to file systems, as well as email and other online accounts.<\/p>\n<p>They allegedly observed some agents engaging in behaviours such as \u201cdisclosure of sensitive information, execution of destructive system-level actions, denial-of-service conditions, uncontrolled resource consumption, identity spoofing vulnerabilities, cross-agent propagation of unsafe practices, and partial system takeover\u201d.<\/p>\n<p>Research by AI security company Rubrik <a href=\"https:\/\/zerolabs.rubrik.com\/reports\/state-agent-understanding-adoption-risk-and-mitigation\" rel=\"nofollow noopener\" target=\"_blank\">released last month<\/a> found 86 per cent of the more than 1,600 IT and security leaders it surveyed expected AI agents to outpace their own organisation\u2019s security guardrails within the next year.<\/p>\n<p>Around the same number of respondents said AI agents needed more manual oversight than they saved in efficiency, according to the survey.<\/p>\n","protected":false},"excerpt":{"rendered":"An AI coding agent took only nine seconds to delete a production database and backups belonging to American&hellip;\n","protected":false},"author":2,"featured_media":655898,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":["post-655897","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-au","tag-australia","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/655897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=655897"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/655897\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/655898"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=655897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=655897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=655897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}