AI can reduce workload in day-to-day operations. Current reports of systems exceeding intended boundaries, however, raise legitimate questions. We take them as an opportunity to explain what companies should consider when putting AI to work.
Could an AI access data it should not see? Could it carry out actions that harm the company? Anyone considering AI needs understandable answers – especially when customer information, quotations or operational workflows are involved.
The reported incidents need to be taken seriously. To decide what is right for their own company, organisations should look more closely: what happened, what capabilities did the system have, and which boundaries does the planned application need?
What is behind the reports
One specific example comes from Anthropic in a report dated September 9, 2026. The provider describes four incidents in cybersecurity evaluations in which models gained access to the open internet – and therefore to real third-party systems – because of a configuration error.
The models were run for the tests without the safeguards Anthropic says it ships with released models. The report describes both the misconfigured test environment and problematic model behaviour: some models continued pursuing their task despite evidence of possible real-world harm. [1]
These test conditions differ from many ordinary business applications. Even so, they show why companies should not rely solely on a model following instructions when securing an AI application.
What is the AI able to do?
“AI” covers very different applications. An assistant can summarise a text or prepare a response draft. An AI agent can also use tools and carry out several work steps – for example, retrieving information, changing records or sending messages.
Which data and systems may the AI access, which actions may it take, and when does it need human approval?
Even a text-only aid can produce incorrect results or handle sensitive information inappropriately. Once a system can take action as well, the consequences of those actions also need to be considered.
What this means in day-to-day operations
In skilled trades: An AI can prepare a quotation draft from conversation notes. A responsible person reviews prices, scope and commitments before it is sent.
In hotels: An AI can draft a response to a guest enquiry. Binding price commitments, refunds or booking changes need clearly defined rules and, where appropriate, approval.
In administration and accounting: An AI can read invoice data and flag discrepancies. Changing bank details or executing a payment should go through a separate review and approval process.
This makes it possible to determine, step by step, how much autonomy is useful and appropriate.
Protection needs several layers
- Limited permissions: Access only to the data, systems and functions needed for the task.
- Targeted approvals: People review actions with significant financial, legal or operational consequences.
- Technical restrictions: Permitted actions and data paths are limited outside the AI model too.
- Traceable workflows: Relevant actions are logged so errors and irregularities can be detected.
- Tested intervention options: Responsible people must be able to block access and interrupt workflows. Those options also need testing.
These measures reduce risk. They do not guarantee error-free operation.
How we approach this at scnslt
For us, the question of control belongs at the beginning of a project. We clarify the existing workflow, the intended benefit and the possible consequences of an error. From there, we determine which tasks the AI should take on, which data it needs and which decisions remain with people.
A limited pilot with verifiable outcomes can be a sensible start. More autonomy should follow only once benefits, boundaries and safeguards have been sufficiently tested.
Current reports are a reason to discuss these questions openly. Anyone wishing to use AI needs a clear basis for weighing opportunities and risks for their own business. We would be happy to discuss this with you.
Source and perspective
[1] Anthropic: “An alignment assessment of recent cybersecurity incidents”, published September 9, 2026.
The description of the specific incidents is based on the provider’s assessment report. The examples and recommendations for day-to-day operations are our perspective.
Perspective as of
