Home/News/AI agents miss one in three threats when humans approve commands
Web Dev

AI agents miss one in three threats when humans approve commands

WHAT THIS MEANS FOR YOUR BUSINESS

Blindly trusting AI automation approvals puts your data and customers at risk more often than most business owners realise.

06 Aug 2026|4 min read|
Business AutomationSecurityAI ToolsSmall Business

If you are starting to let AI tools take actions on your behalf, a new piece of research suggests you should think carefully about who is actually minding the shop.

The Problem With Assuming Someone Is Watching

A study analysing over 40,000 runs of AI agents completing tasks found that human reviewers missed roughly one in three potentially risky commands they were supposed to catch. These were not complex, deeply buried actions. They were the kind of routine approvals that feel low-stakes until they are not.

This matters because AI agents are no longer just answering questions or drafting emails. They are increasingly being given the ability to take actions: booking things, sending messages, updating records, making purchases. Businesses are adopting these tools precisely because they save time by reducing the need for human involvement. The uncomfortable finding here is that the human oversight which is supposed to serve as a safety net is far weaker than most people assume.

Oversight Fatigue Is a Real Business Risk

Here is what actually happens in practice. You set up an AI tool to handle a chunk of repetitive work. You put in an approval step because it feels responsible. Then, because approvals come through constantly and almost all of them are fine, you start clicking through quickly. Your attention drifts. And that is exactly the moment something slips through.

The research does not describe a dramatic hack or a rogue system. It describes ordinary human attention failing under the pressure of volume and routine. Any business owner who has ever signed a stack of invoices without reading each one carefully will recognise this pattern immediately.

The approval button only works if someone is genuinely reading what they are approving.

What This Means If You Are Automating Tasks Right Now

If you are using AI tools that have any kind of real-world reach, whether that means sending communications to customers, updating your website, processing orders, or managing files, the risk profile is higher than it looks on paper. The tools themselves may be performing exactly as intended. The gap is in how humans interact with the guardrails around them.

For small businesses, the stakes are arguably higher than for larger ones. You do not have a dedicated team reviewing AI outputs. It is probably you, or one trusted member of staff, fitting approvals in between everything else the day throws at you. A missed instruction that routes a customer email to the wrong person, or triggers an unintended purchase, lands directly on your plate to clean up.

The good news is that the fix is not "stop using AI tools." It is "be deliberate about what you actually let them do unsupervised." A narrow set of well-defined actions with genuine review is far safer than a broad capability with a theoretical human in the loop.

What To Do About It

  1. 1.List every action your AI tools can take on your behalf. Not what they can suggest or draft, but what they can actually do: send, publish, purchase, delete, contact. If that list is longer than you expected, treat it as a warning sign worth investigating this week.
  1. 1.Reduce the approval volume to reduce the fatigue. If you are clicking through dozens of AI-generated approvals a day, redesign the setup so only genuinely consequential actions need your sign-off. Fewer, more meaningful reviews beat many meaningless ones every time.
  1. 1.Set hard limits on irreversible actions. Deleting records, sending bulk communications, making payments; these should require a deliberate extra step rather than sitting in the same approval queue as low-stakes tasks. Most tools allow you to configure this.
  1. 1.Review what happened last week, not just what is happening now. Build a ten-minute weekly habit of scanning what your AI tools actually did, not just what you approved. Patterns you would never spot in real time often become obvious in a short retrospective.
SOURCES
[1] Humans missed 1 in 3 threats approving AI agent commands across 40k game runs
https://scalex.dev/blog/ai-agent-permissions-stats/
Published: 2026-08-06
[2] Beating GPT-5.6 Sol on retrieval with 100x cheaper open models
https://neon.com/blog/how-castform-neon-beats-frontier-models-on-price-and-efficiency
Published: 2026-08-05
[3] WordPress 7.1 Accessibility Change May Break Some Plugins via @sejournal, @martinibuster
https://www.searchenginejournal.com/wordpress-7-1-accessibility-change-may-break-some-plugins/584820/
Published: 2026-08-06

GET THE WEEKLY BRIEFING

One email a week. What happened in tech and why it matters to your business.

NEED HELP WITH THIS?

That is literally what we do. Websites, automation, AI tools that actually earn their keep. One conversation, no jargon.

GET IN TOUCH