# Agentic AI needs an undo button

> Source: <https://www.businesstimes.com.sg/opinion-features/agentic-ai-needs-undo-button>
> Published: 2026-09-14 08:19:14+00:00

# Agentic AI needs an undo button

Recoverability should determine how much autonomy enterprises give AI agents

IN JULY and August 2026, OpenAI, Anthropic and Meta disclosed separate cybersecurity-evaluation incidents in which models crossed intended test boundaries and reached external systems.

In the [Anthropic](https://www.businesstimes.com.sg/startups-tech/technology/anthropics-ai-models-hack-three-organisations-during-tests) and [Meta](https://www.businesstimes.com.sg/companies-markets/telcos-media-tech/meta-ai-model-hacks-another-company-during-testing) cases, misconfigured evaluation environments provided unintended Internet access. In [OpenAI’s case](https://www.businesstimes.com.sg/startups-tech/technology/openai-agents-hacked-hugging-face-700-strong-swarm-tried-cover-tracks-investigations-find), models exploited a previously unknown vulnerability in an internally hosted intermediary service, enabling them to access the Internet and reach the production environment of another company, Hugging Face.

The lesson is not that AI has developed malicious intent, but that an agent, given an objective, network access and too much authority, can turn an overlooked weakness in its environment into a real-world action.
