Tickd.ai
← The Tickd Guide

Ethics & Responsible Use

When AI Can Act, Not Just Answer: The Risks of Agentic AI

A wrong answer costs you a re-prompt. A wrong action costs you money, data or reputation. What changes when models get hands.

Updated 9/13/2026

For three years the failure mode was a confident wrong answer. Annoying, contained, easy to catch. Agents change the shape of the problem: the same unreliability now has permissions attached.

What an agent actually is

A model in a loop with tools. It plans, calls something — a browser, a shell, your email, a payments API, your files — reads the result and continues. That is it. The intelligence is not new; the authority is.

The genuinely new risks

Compounding error. A single 95%-reliable step is fine. Twenty chained steps at 95% is a coin flip, and step nine's mistake becomes step ten's premise. Agents are confident narrators of their own drift.

Prompt injection. This is the one to understand. An agent that reads web pages, emails or documents is reading text written by strangers, and it has no reliable way to distinguish instructions from you from instructions embedded in that content. A hidden line on a page can tell your agent to exfiltrate what it has already read. There is no known complete fix — mitigations reduce the rate, they do not close the class.

Excess permission. Convenience pushes towards broad scopes: full mailbox access, write access to a repository, a saved card. The blast radius of a misstep is exactly whatever you granted.

Irreversibility. A sent email, a posted message, a placed order, a deleted file. Undo is a product feature, not a property of the world.

Diffuse accountability. When an agent, a framework, a model provider and a tool integration jointly produce a bad outcome, responsibility is genuinely unclear — legally and organisationally. That ambiguity is itself a risk.

The disagreement

Optimists argue this is a familiar security problem: sandbox, scope, log, review, and treat agent output as untrusted input the way we already treat user input. Nothing here is unprecedented, and the productivity is worth the engineering.

Sceptics reply that a component which can be talked into anything by content it must read is unlike previous software, and that shipping such components into finance, email and infrastructure before the injection problem has a real solution is optimism dressed as pragmatism.

A third view holds that both are arguing about capabilities agents do not reliably have yet, and that most current deployments fail from mundane brittleness long before anything dramatic happens.

All three describe something true about the present moment.

Practical rules that hold either way

Give the narrowest credential that completes the task, and prefer read-only. Require confirmation before anything that spends money, sends a message or deletes data. Keep agents out of unfiltered inbound content, or treat everything they read as hostile. Log every action with enough detail to reconstruct the sequence. Cap spend, steps and time. Run destructive work in a throwaway environment. And keep a human on any decision with a legal, financial or reputational tail.

If you are planning something agentic, our build roadmap tool will scope the phases, and the platform pages note where each provider's tool-use is currently strongest. Related: the alignment problem, explained simply.

ethicsagentssecurityai-risk

Keep going

Build something with the prompt generator, decode the jargon in the glossary, or compare the tools on our platform deep-dives.