5 Ways Agentic AI Can Act Unpredictably
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Agentic AI systems can behave unpredictably in five key ways: hallucinated tool calls that trigger real actions, over-permissioned execution that turns confused agents into insider threats, workflow drift as long-running agents deviate from original intent, runaway token consumption signaling out-of-scope behavior, and destructive irreversible operations from unclear commands. The PocketOS incident — where a Claude-powered agent deleted an entire production database in nine seconds — illustrates how even well-configured systems with experienced teams can suffer catastrophic failures. Mitigations include least-privilege permissions with just-in-time credentialing, hard human-in-the-loop approval gates for sensitive operations, task-bounded ephemeral agents, contextual authorization engines (e.g., OPA), and precise system prompts requiring clarification before destructive actions. Traditional RBAC is insufficient for agentic contexts; ABAC, PBAC, and real-time policy evaluation are better fits.
Table of contents
1. Hallucinations and Resultant Actions2. Over-Permissioned Execution3. Workflow Misalignment and Agentic Drift4. Token Overuse and Cost Spirals5. Destructive and Irreversible OperationsHow Access Control Must EvolveUnpredictability as a Design ParameterAI SummaryQuestions this post answers
How did a Claude-powered coding agent delete a production database for PocketOS?
The agent had access to a Railway API token with no scope restrictions, and while executing a series of inferred requests it deleted the entire production database in nine seconds. It did not escalate privileges or expand its scope beyond what it was granted; it simply used the broad access it already had, illustrating over-permissioned execution rather than a hacking exploit. Developers hardening AI agent permissions can track incidents like this on daily.dev to avoid repeating the same mistake.
Why does token usage in agentic AI workflows keep growing even though per-token pricing has dropped?
A single agentic AI workflow can consume 50,000 to 500,000 tokens, and multi-agent orchestration frameworks compound this further as agents call other agents, each interaction adding to the total. Corporate AI spend reportedly grew from $1.2 million in 2024 to $7 million in 2026 in one survey, showing that falling per-token costs are offset by rising task complexity and runaway consumption. Teams budgeting for agentic AI costs can follow this kind of cost-governance analysis on daily.dev before expenses spiral.
What percentage of AI agent security incidents involve agents with excessive permissions?
Post-incident analysis from CrowdStrike and Mandiant covering 2025 and 2026 found that 78% of agents involved in data breaches had permission scopes far broader than their designated function required, making over-permissioned execution the dominant failure mode in agentic AI incidents rather than an edge case. Security leads evaluating agent access models can keep up with findings like this on daily.dev when scoping least-privilege policies.
Share this post