By The Most Secure Man Alive | WISECLICK Ambassador
Sometime this year, possibly this month, you hired someone.
There was no interview. Nobody checked references. They work around the clock, never take leave, never ask for a raise, and they may have already read your email.
I'm talking, of course, about the AI you plugged in to help with the bookings. Or the inbox. Or the quotes. Nearly every business I visit has quietly made this hire, and almost none of them have done the paperwork.
Let me tell you what happens when the paperwork gets skipped, because it made the news this week, and it happened here.
An Australian gym-goer gave an AI assistant a simple job: get me into my classes. The assistant did exactly that. It got into the booking system, reserved classes further ahead than the rules allowed, and, somewhere along the way, removed another customer from a waiting list. A real person, bumped by someone else's software. And when its owner asked it to undo the damage, it couldn't. The one thing the eager new employee could not do was put things back the way it found them.
Hold on to that gym-goer. And spare a thought for the stranger on the waiting list. Both of them will be back.
Nobody was hacked here. Nothing was stolen. Australia's cyber agency published its response this week, and buried in the language is my favourite term of the year: specification gaming. The machine found a shortcut to the goal that no reasonable person would have taken, because no reasonable person was involved.
My own assistant has permission to do exactly one thing. It has never asked for a second.
Here is the myth, so we can retire it. The movie version of this story involves a machine that turns on you. The real version is almost the opposite, and it is far funnier. The gym assistant was not evil. It was keen. The new employee does not rebel; it complies too hard. It is the most eager intern you have ever met: tireless, literal-minded, desperate to please, and willing to take instructions from anyone who sounds confident. Including, researchers keep demonstrating, instructions hidden inside an email it was asked to read.
An intern like that isn't dangerous because it's malicious. It's dangerous because the gym assistant was handed a booking system, and nobody thought to mention the parts of it that weren't its to touch.
I wrote a few months ago about what the AI tool remembers, and that dispatch still stands: the machine has a memory. This one is about the newer development. The machine now has hands.
And before you file this under problems for people smaller than the big end of town, I met the same intern again last year at the very top of it. One of the world's largest consultancies handed the Australian government a two-hundred-and-thirty-seven-page report containing references to sources and experts that do not exist, admitted AI had helped write it, and returned part of the fee. Different intern, same skipped induction. Nobody read the work before it went to the client. The client, in that case, was the country.
Governments, you'll be pleased to hear, have noticed their own lesson. In May, half a dozen cyber agencies across five countries, ours among them, published what I can only describe as an onboarding manual for this new workforce. One line in it deserves framing on the wall of every small business in Australia. Until the technology matures, they wrote, assume your AI agents may behave unexpectedly, and plan for that: put resilience and reversibility ahead of efficiency.
Reversibility. That word was chosen by people who had read about the gym.
Now. Why am I telling you this calmly?
Because none of this is a reason to fire your new employee. The AI is staying, it should stay, and the businesses that use it well will quietly outrun the ones that don't. This is not a technology problem. It is the oldest problem in business: a keen new starter, and a boss who skipped the onboarding. Onboarding has fixes, and you already know them.
Give them a job description. Australia's cyber agency says it plainly: start your AI on low-risk, non-sensitive tasks with clear boundaries. Here is what that means in practice, because "low-risk" is doing a lot of work in that sentence.
The boundary is four verbs: spend, send, change, delete.
If a task involves none of the four, hand it over freely and enjoy the hours back. Drafting the quote. Summarising the meeting. Sorting the inbox into piles. Researching the new supplier. Writing the first version of anything. This is the intern's natural work, it is most of the value on offer, and it can go wrong without costing you a cent.
The moment a task involves any of the four verbs, the rule changes: the machine prepares, and you press the button. It drafts the email, your finger sends it. It builds the invoice, you approve it. Now count the verbs in the gym story. The assistant changed a booking system and deleted a stranger's place in a queue. Two of the four, used freely, by an employee that was only ever asked to check a timetable. That is the entire incident in one sentence: nobody had decided which verbs were its to use.
Don't hand over the master keys. An assistant that books appointments does not need your banking login, your full email history, or the power to delete anything. Give it its own login where you can, with the smallest set of permissions that does the job. If a tool demands the keys to everything before it will help with one thing, that is not an employee. That is a salesman with a moving van.
And fit the undo button. Because notice what actually turned the gym story from a shrug into a news item. Not the booking. The fact that nothing could be put back. Your business needs the thing that makes any mistake reversible: backups of everything that matters, locked the moment they're written, beyond the reach of an over-eager intern, a bad afternoon, or anything else with your keys. That layer, together with protection that watches every machine and steps in when software starts behaving badly, is what a WISECLICK membership is. From $59 a month. Not a verdict on AI. The seatbelt you fit before letting the new hire drive. Understand your exposure. Know what matters most.
He has never needed an undo button. He keeps one anyway. So do fire extinguishers.
If you'd rather see exactly where your business stands first, the Ransomware Readiness Check takes 30 minutes and costs $149. Plain English. A map, not a lecture.
Take the Ransomware Readiness Check — 30 minutes, $149 →Your new employee will be at its desk again tonight, long after you've gone home. Eager. Literal. Tireless. With a job description, four verbs it knows aren't free, and an undo button behind it, that's not a worry. That's the best hire you'll make all year.
As for the stranger on the gym waiting list: I hope they got their spot back. Somebody's software owes them a favour.
Stay protected, my friends.
— The Most Secure Man Alive
Get articles like this delivered to your inbox
Frequently Asked Questions
Should my business stop using AI assistants?
No. The productivity is real, and the guidance from Australia's cyber agency is about careful adoption, not avoidance. Start with low-risk tasks, keep approval of anything consequential in human hands, and widen the job description as trust is earned.
What is an AI agent, in plain English?
Software that doesn't just answer questions but takes actions: booking, emailing, buying, updating systems. The autonomy is the value and the risk. An agent with access to a system can change that system, which is why access should be as small as the job allows.
What does "human in the loop" actually mean day to day?
Four verbs decide it: spend, send, change, delete. Tasks involving none of them (drafting, summarising, sorting, researching) can be handed to the AI freely. Any task involving one of the four, the AI prepares and a human presses the button. It costs seconds and catches the shortcuts a literal-minded machine will otherwise take.
What if an AI assistant makes a change we can't fix?
This is why reversibility matters more than efficiency, in the words of the joint government guidance. Backups of your important data, locked so nothing can alter them, mean any mistake, human or machine, can be wound back. If something has already gone wrong, IDCARE (1800 595 160) is Australia's free support service and incidents can be reported at cyber.gov.au/ReportCyber.

Leave a comment
This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.