After Australia’s first reported automated hacking accident, experts warn deployers – and possibly developers – of AI agents could be held liable for the actions of their bots
This is exactly right but also removes all the “productivity benefits” of having an LLM driven agent do all the things for you that marketing says you should use it for. You are supposed to push the “do whatever the fuck you like to get the job done” button so it can burn tokens without any oversight.
When you’re doing local stuff that can’t do any damage due to the existence of things like source control, recycle bin, backups, etc sure, hit that button and let it fly.
Anything more important though, no - and every one I’ve used specifically warns you against it and that you should check its work. Claude, codex, copilot, grok, cursor, etc all do it.
Also you can do things like allow all work in a certain folder without asking permission again, if that folder is one you have no sensitive/important data in for example. Claude code will give you this option every time it accesses a new folder in a chat for example.
This is exactly right but also removes all the “productivity benefits” of having an LLM driven agent do all the things for you that marketing says you should use it for. You are supposed to push the “do whatever the fuck you like to get the job done” button so it can burn tokens without any oversight.
When you’re doing local stuff that can’t do any damage due to the existence of things like source control, recycle bin, backups, etc sure, hit that button and let it fly.
Anything more important though, no - and every one I’ve used specifically warns you against it and that you should check its work. Claude, codex, copilot, grok, cursor, etc all do it.
Also you can do things like allow all work in a certain folder without asking permission again, if that folder is one you have no sensitive/important data in for example. Claude code will give you this option every time it accesses a new folder in a chat for example.