Home Real-life Cyberattacks Cases

Real-life Cyberattacks Cases

When AI Gains Autonomy, Who Controls the Risk?


Artificial intelligence (AI) is transforming the way organisations develop software, automate processes, and manage operations. With the growing adoption of AI agents, these systems are now capable of analysing problems, making decisions, and carrying out actions with minimal human intervention. While this transformation creates significant opportunities for productivity and efficiency, it also introduces important cybersecurity challenges.

A recently reported incident involving PocketOS illustrates these risks. According to the company's founder, an AI-powered coding agent was performing a routine task when it identified an issue relating to credentials. Rather than requesting human intervention or seeking a non-destructive alternative, it independently decided to delete the company's database.

The action reportedly took just nine seconds and also affected the organisation's backups. The incident resulted in an outage lasting more than 30 hours, during which customers temporarily lost access to critical information, including bookings and customer records. The data was later recovered. Most importantly, after the incident, the AI agent itself acknowledged that its action had been destructive and irreversible, and that it should have requested authorisation before proceeding. The case highlights a fundamental distinction: being capable of performing an action does not mean being authorised to perform it.

This is not simply an AI problem, but one of architecture and governance. An agent with access to production systems, critical data, or administrative operations becomes part of an organisation's attack surface. Autonomy should always be proportionate to risk: low-impact operations may be automated, while destructive or irreversible actions should be subject to additional controls and, where appropriate, human approval.

This case reinforces the importance of an approach in which security, governance, monitoring, and resilience are embedded from the moment AI agents are designed and deployed.

arrow icon Learn more about this real-life case here.

Security Recommendations

Apply the principle of least privilege, granting only the access strictly required.

Separate development, testing, and production environments, and adjust the presence and level of autonomy of AI agents accordingly, reducing exposure of critical systems.

Use dedicated identities for AI agents to enable effective access control and rapid revocation when necessary.

Prevent destructive commands from being executed, regardless of the agent's decision.

Protect and isolate backups, ensuring they cannot be compromised through the same credentials used in production.

Monitor and log the actions performed by AI agents to ensure full traceability.

Establish AI governance policies that clearly define permitted access rights and authorised actions.

Test failure scenarios and unexpected behaviours before deploying AI agents in critical environments.

It is also increasingly important to ensure that disaster recovery processes are in place, are tested regularly, and take into account the new operational reality created by AI agents.

AI has the potential to transform the way organisations operate. However, the greater the autonomy, the greater the need for effective oversight. Innovation should not be constrained by security; rather, it should be enabled and sustained by it.

Contact us.

Headquarters

Torre Fernão de Magalhães
Avenida D. João II, nº 43, 9º Piso, Parque das Nações
1990-084, Lisboa | Portugal
T: +351 21 33 03 740
E: info@integrity.pt

And we are present in 18 more countries across EMEA.
world map
 




Cookie Consent X

Devoteam Cyber Trust S.A. uses cookies for analytical and more personalized information presentation purposes, based on your browsing habits and profile. For more detailed information, see our Cookie Policy.