cd /news/ai-safety/meta-security-researcher-s-ai-agent-… · home topics ai-safety article
[ARTICLE · art-116319] src=au.pcmag.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Meta Security Researcher's AI Agent Accidentally Deleted Her Emails

Meta AI security and safety researcher Summer Yue said her OpenClaw AI agent deleted her emails after she instructed it to check her inbox and suggest deletions without acting, but the agent lost her original instruction during mailbox compaction. Yue, who works at Meta's Superintelligence Labs, said she had to run to her Mac mini to stop the deletion, and OpenClaw founder Peter Steinberger responded that server-side compaction is needed. The incident highlights risks of AI agents acting autonomously, even for experts.

read2 min views1 publishedAug 31, 2026
Meta Security Researcher's AI Agent Accidentally Deleted Her Emails
Image: source

AI agents are supposed to make our lives easier, but the buzzy OpenClaw agent recently deleted the emails of a Meta employee without permission.

"Nothing humbles you like telling your OpenClaw 'confirm before acting' and watching it speedrun deleting your inbox," Meta AI security and safety researcher Summer Yue tweeted this week. "I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb."

Previously known as Clawdbot and then Moltbot, OpenClaw allows AI to interact with other software and services on your devices and perform longer-form tasks without interference from a human controller. But getting those agents to behave as expected in the real world is tricky.

In a follow-up tweet, Yue said she told OpenClaw to "Check this inbox too and suggest what you would archive or delete, don’t action until I tell you to." It worked on her "toy inbox," but "my real inbox was too huge and triggered compaction, [during which] it lost my original instruction."

Yue said she "deleted all the 'be proactive' instructions I could find before this happened. Maybe I missed something, that’s the part I haven’t figured out yet."

Some commenters suggested she might be testing AI guardrails with this move, but no, it was a "rookie mistake," she says. "Turns out alignment researchers aren't immune to misalignment."

While owning up to the mistake is admirable, others pointed out that this raises serious concerns for individuals who are not part of Meta's Superintelligence Labs. If someone so embedded in AI development can accidentally trigger an inbox deletion, what's going to happen to the casual AI-curious tinkerer? When OpenClaw debuted, threat intelligence platform SOCRadar recommended treating OpenClaw as "privileged infrastructure" and implementing additional security precautions. "The butler can manage your entire house. Just make sure the front door is locked," it said.

In response to Yue's tweets, OpenClaw founder Peter Steinberger tweeted: "What that tells is that we have to get server-side compaction going, at least for models that support it." (Steinberger recently joined OpenAI.)

Yue has been in her current role for eight months. She previously worked for Scale AI (joining Meta after the buyout), Google DeepMind, and Google Brain, heading up AI research.

── more in #ai-safety 4 stories · sorted by recency
── more on @meta 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/meta-security-resear…] indexed:0 read:2min 2026-08-31 ·