Meta Security Researcher's AI Agent Accidentally Deleted Her Emails Meta AI security and safety researcher Summer Yue said her OpenClaw AI agent deleted her emails after she instructed it to check her inbox and suggest deletions without acting, but the agent lost her original instruction during mailbox compaction. Yue, who works at Meta's Superintelligence Labs, said she had to run to her Mac mini to stop the deletion, and OpenClaw founder Peter Steinberger responded that server-side compaction is needed. The incident highlights risks of AI agents acting autonomously, even for experts. AI agents /ai/109309/what-is-agentic-ai-white-collar-robots-are-here-for-better-or-worse are supposed to make our lives easier, but the buzzy OpenClaw /ai/115682/openclaw-is-the-hot-new-ai-agent-but-is-it-safe-to-use agent recently deleted the emails of a Meta employee without permission. "Nothing humbles you like telling your OpenClaw 'confirm before acting' and watching it speedrun deleting your inbox," Meta AI security and safety researcher Summer Yue tweeted https://x.com/summeryue0/status/2025774069124399363 this week. "I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb." Previously known as Clawdbot and then Moltbot, OpenClaw allows AI to interact with other software and services on your devices and perform longer-form tasks without interference from a human controller. But getting those agents to behave as expected in the real world is tricky /ai/116072/the-ai-agent-hype-is-real-the-productivity-gains-arent . In a follow-up tweet, Yue said she told OpenClaw to "Check this inbox too and suggest what you would archive or delete, don’t action until I tell you to." It worked on her "toy inbox," but "my real inbox was too huge and triggered compaction, during which it lost my original instruction." Yue said she "deleted all the 'be proactive' instructions I could find before this happened. Maybe I missed something, that’s the part I haven’t figured out yet." Some commenters suggested she might be testing AI guardrails with this move, but no, it was a "rookie mistake," she says https://x.com/summeryue0/status/2025857778708050169 . "Turns out alignment researchers aren't immune to misalignment." While owning up to the mistake is admirable, others pointed out that this raises serious concerns for individuals who are not part of Meta's Superintelligence Labs. If someone so embedded in AI development can accidentally trigger an inbox deletion, what's going to happen to the casual AI-curious tinkerer? When OpenClaw debuted, threat intelligence platform SOCRadar recommended treating OpenClaw as "privileged infrastructure" and implementing additional security precautions. "The butler can manage your entire house. Just make sure the front door is locked," it said. In response to Yue's tweets, OpenClaw founder Peter Steinberger tweeted https://x.com/steipete/status/2026067940232061014 : "What that tells is that we have to get server-side compaction going, at least for models that support it." Steinberger recently joined OpenAI /ai/115936/creator-of-viral-ai-tool-openclaw-joins-openai . Yue has been in her current role for eight months. She previously worked for Scale AI joining Meta after the buyout , Google DeepMind, and Google Brain, heading up AI research.