Security researchers highlight need for guardrails on consequential actions
3 Sep 22 5:08 AM · 4d ago · 1 comment · 1 source · development 3 of 5
Commenters argued that while AI agents reading contracts is acceptable, applying signatures and preparing to send them must require explicit human approval. One noted the distinction between benign and consequential agent behavior.
“If you're willing to give Claude or any other AI tool access to your email and files, the least you should do is put guardrails around consequential actions. Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.”
ayanivfranze Developer who reported the incidentAnthropic Creator of Claude Code agent
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
What people said 2 voices · verbatim
-
You hooked up a chatbot to a harness that does API calls to myriad services. That's what you did. "Claude by himself" did not "do" anything. Just like they did not "break out of containment" and hacked companies.
-
And you are happy because that is what you wanted and the reason why you gave a randomness machine access to your mails, correct?
All 5 developments of Claude Code autonomously signs contract without user consent →
Hacker NewsNewswires