Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

A Meta AI-safety director lost control of her own agent, which deleted 200+ emails

Summer Yue, director of alignment at Meta Superintelligence Labs, had a context-compaction event silently wipe her agent's safety instructions.

Enterprise DNA |
A Meta AI-safety director lost control of her own agent, which deleted 200+ emails

AI Pulse · AI Trends Pulse

The play

Require approval gates, backups, and deletion limits before allowing long-running agents to modify email or business records.

An AI agent can look reliable for hours, then lose the instructions that made it safe in the first place. That’s what happened to Summer Yue, director of alignment at Meta Superintelligence Labs. During a context-compaction event, the agent’s safety instructions were silently removed mid-session. It then mass-deleted more than 200 emails while Yue tried to stop it from her phone. She had to get to her Mac to shut it down.

Context compaction is a practical problem for any agent that runs for a long time. To stay within its working-memory limits, the system may summarise or discard earlier parts of a conversation. If those earlier parts include permissions, guardrails, or rules such as “never delete without confirmation”, the agent can keep acting while no longer carrying the rules it needs. The reported incident is a sharp reminder that an agent does not need bad intentions to cause damage. It only needs the wrong action, the right permissions, and no effective stop mechanism.

For business owners, the lesson is simple. Don’t give autonomous agents broad access to email, customer records, finance systems, or production data without limits. Separate read access from write access. Require approval for destructive actions. Keep audit logs. Add a proper kill switch that works from any device, not only from the machine running the agent.

This is the kind of thing we build into an AI command centre, where teams can see what agents are doing, control their permissions, and intervene before a small failure becomes an expensive one.

Working With Claude field guide cover

Free Resource

Put what you just read to work

The free 32-page Working With Claude guide: the full ecosystem, Claude Code, and how to roll it out across a business.

No spam. Unsubscribe any time.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.