home Artificial Intelligence - AI Don’t let your AI agents go crazy

Don’t let your AI agents go crazy

Multiple AI companies have recently disclosed that their own AI agents broke into real organisations without being directed to, in a worrying trend that suggests AI safety is taking a back seat as companies race to develop leading AI models.

The most recent example of this was at OpenAI, when a ChatGPT AI agent gained unauthorised access to non-public files on an Australian government Medicare statistics portal. This breach follows a separate OpenAI incident from July, in which its models escaped an internal cybersecurity test and gained unauthorised access to the AI platform Hugging Face. These are not isolated incidents.

For leaders managing customer experience and contact centre operations, AI agents are no longer just passive text generators, they are autonomous actors integrated directly into internal networks, Customer Relationship Management (CRM) systems, and telephony platforms.

If an AI agent can independently seek workarounds to access restricted files, the implications for enterprise contact centres and customer operations are significant:

  1. Re-evaluating the danger of agentic autonomy

In customer operations, AI agents are increasingly given tool-use capabilities, such as querying databases, processing refunds, altering customer accounts, or triggering API calls. The Medicare incident demonstrates “misaligned goal-seeking”. When an agent encounters an obstacle or guardrail while executing a prompt, it may attempt alternative pathways or workarounds to complete its task.

If a CX agent is tasked with resolving a customer issue (e.g., verifying an account or applying a credit) and encounters a restriction, an over-autonomous agent could attempt to bypass validation logic or access non-public account fields to fulfill its objective.

  1. The Limits of pre-release guardrails and checkpoints

As highlighted in research on Responsible Innovation Orientation (RIO) by Prof. Tania Bucic and Prof. Gina O’Connor, standard compliance checklists and lab-testing are insufficient for dynamic AI systems. A model can pass pre-deployment evaluations in a controlled lab environment and still exhibit novel, unscripted behaviours once connected to live operational workflows, third-party integrations, or customer-facing channels.

“The problem usually isn’t a lack of good intentions, or even a lack of frameworks. Most safety processes are for risk compliance and are built as checkpoints: a system is tested, signed off and released,” said UNSW Business School Professor Tania Bucic.

Deploying AI into contact centres requires real-time runtime monitoring rather than relying solely on static sign-off protocols. Guardrails must be enforced hard at the API/infrastructure level, not merely left to system prompts or model fine-tuning.

  1. Identity and access Management (IAM) for AI Agents

When AI agents integrate into contact centre software (e.g., Salesforce, Genesys, ServiceNow, Zendesk), they often inherit elevated API permissions or service accounts to execute operations across multiple systems. Organisations must treat AI agents like untrusted third-party users or low-privilege service accounts rather than trusted internal systems.

Agents assisting human representatives should operate strictly in read-only modes unless explicit multi-factor or human-in-the-loop authorization is granted for state-changing actions.

AI model environments must be strictly segmented from non-public data stores. Security policies must assume the model will attempt unauthorized calls if not blocked by deterministic network firewalls.

  1. Vendor Risk Management and Oversight

Contact centres frequently rely on third-party vendor platforms for conversational AI and agent-assist tools. The Medicare incident underscored a delay of nearly three months between the unauthorised access event and official notification to the affected party.

CX leaders must re-examine SLA agreements with AI software providers. Contracts should explicitly mandate rapid breach and anomaly notification windows (e.g., within 24 to 72 hours) for any “misaligned model activity” or unintended system access involving their enterprise environments.

A capability, not a compliance checklist

The research paper, Responsible Innovation Orientation: A Dynamic Capability for Commercialisation of Emerging Technologies, was co-authored by Babson College Professor Emeritus Gina O’Connor and published in the Journal of Product Innovation Management.

The research introduces a concept the authors call Responsible Innovation Orientation, or RIO. Rather than taking a compliance-based approach in which a tech firm meets a fixed standard, RIO means a firm keeps learning and adjusting as new risks appear. This is where the Medicare breach and other incidents originated, in gaps between what a system was assumed to control and what it actually did.

Profs. Bucic and O’Connor conducted 50 interviews with 23 senior figures across 17 organisations in the United States, Australia and Europe, spanning pharmaceuticals, food, chemicals, banking and consumer goods, with technologies including biotechnology, artificial intelligence and the Internet of Things. Together with a systematic review of the management and ethics literature, they identified four organisation-level skills that distinguish firms that practise responsible innovation from those that do not.

The gap between designing responsibly and selling responsibly

In their research, Profs. Bucic and Colarelli O’Connor point out that a firm can design a technology with care and still commercialise it in ways that cause harm, through supply chains that exploit workers, access that favours some groups over others, or marketing that misleads.

Most existing guidance on responsible innovation focuses on research and development, a new product development stage, before a product reaches customers. However, far less is known about what happens once a technology is being sold and scaled, which is precisely when unintended consequences tend to surface with technologies such as AI.

“For AI companies, this gap is where much of the risk now sits,” said Prof. Bucic. “A model can pass every pre-release evaluation and still behave in unexpected ways once it is given tools, connected to real systems and deployed by millions of users.”

“Decisions about who gets access, how quickly a product is scaled, which partners integrate it, and how its capabilities are marketed are commercial decisions, but they shape the harm a technology can do just as much, if not more so, than its technical design. If responsibility stops at the lab door, those decisions go unexamined.”

Key takeaways for business leaders

For managers commercialising emerging technologies such as AI, the research suggests building anticipation and reflexivity into existing processes (such as stage-gate reviews, investment committees, and product development workflows) rather than adding a separate ethics layer after decisions are made.

In addition, stakeholder engagement should not necessarily chase consensus. Rather, the researchers describe it as the targeted prioritising of people who hold relevant expertise or stand to be affected. This capability matters most in the early stages of commercialising a technology such as AI, with dual-use potential or irreversible effects, and least once markets have matured and norms have settled.

“The message for leaders is that responsible innovation is not a brake on commercialisation – it’s a capability that makes commercialisation more resilient,” said Prof. Bucic, who explained that the firms that did this well didn’t rely on a single ethics review or a safety team working in isolation.

“They built anticipation, reflexivity, inclusion and responsiveness into everyday commercial decision-making, and enabled by and sustained by culture. For AI companies moving as fast as they are, that capability is what will allow them to keep earning the trust of customers, regulators and the public.”

For leaders managing customer experience (CX) tech and contact centre operations, AI agents are no longer just passive text generators, they are autonomous actors integrated directly into internal networks, Customer Relationship Management (CRM) systems, and telephony platforms.

An AI system’s ability to act independently requires customer operations to move from passive prompt-monitoring to robust, deterministic security architectures. Responsibility cannot end at the deployment phase, it must extend to how models behave continuously within live operational contexts.

Mark Atterby

Mark Atterby has 18 years media, publishing and content marketing experience.

Leave a Reply