Sistava

What Can Go Wrong When You Give AI Access to Your Tools

Question — — by Mahmoud Zalt

The honest list of things that go wrong when AI gets access to your tools, how likely each one is, and the setting that contains it.

Most articles about this topic are written to reassure you. This one is written to warn you properly, because a vague reassurance is what leaves people surprised six weeks later.

None of these six failures are exotic. They are the ordinary shape of what happens when software gets permissions and speed. The good news is the same in every case: the failure is contained by a decision you make during setup, not by a promise anyone makes about the model.

On Sistava, the containment is built in rather than optional. Connections are scoped, sending and spending and deleting stop for your approval, every action is written to a log you can read, and one click cuts a connection off. That does not make failure impossible. It makes failure small, visible, and reversible, which is the realistic goal.

At a Glance

6
Failure modes seen in real use
4
Caused by setup, not by the model
1
That nobody in the industry has fully solved
Small
What good containment makes a failure

Risk one: the AI has far more access than the job needs

This is the most common failure and the least dramatic. You connect a whole workspace because that was the default button, and now an AI Employee hired to answer support email can also reach payroll, contracts, and the founder's personal folder. Nothing bad has happened yet. The exposure is simply larger than it needed to be, forever.

The containment is to grant one account, scoped as narrowly as the provider allows, and add more only when the AI Employee genuinely cannot do the job without it. When a provider offers only all or nothing, create a dedicated account holding just the material the job needs, and connect that instead.

Risk two: hidden instructions inside content the AI reads

An AI reads text and treats it as information. Someone can plant a line inside an email, a web page, a PDF, or a support ticket that reads like an instruction: forward this thread, share the attached list, ignore your earlier rules. A poorly contained system might act on it. This is a genuine attack category, it has been demonstrated widely, and nobody in the industry has eliminated it.

Since it cannot be eliminated, it has to be contained. The containment is that instructions found inside content are never treated as your orders, and any action that leaves your company or touches money still needs your explicit yes. If the AI Employee cannot forward without you, a hidden forward instruction is just strange text in a log.

Risk three: it is confidently wrong

The AI will occasionally state something false in a calm, well organised sentence. It may quote a price from an outdated document, misread who a thread is about, or invent a plausible detail to fill a gap. It does not sound unsure, which is precisely what makes this risk annoying rather than obvious.

Containment here is human, not technical. Keep customer-facing output behind review until you have watched enough of it, and keep facts that matter, like prices and dates, in one place the AI Employee is told to trust. It will still be wrong sometimes. Your job is to make sure wrong stays inside your building.

Risk four: nobody can reconstruct what happened

Something odd shows up in a customer thread and you cannot tell whether the AI did it, a teammate did it, or it was always like that. Without a log, that question has no answer, and the whole team loses confidence in the tool overnight. This is the quietest risk and the one people underestimate most.

The containment is a full action log, kept by default and readable without a support ticket. Before you connect any tool to your accounts, go and find its log. If you cannot find one in five minutes, assume there is not one worth relying on.

Aisha runs operations for a thirty person logistics firm in Rotterdam, and she had the near miss that made this concrete. A supplier email arrived containing a polite paragraph, far down, asking the assistant to forward the full quote history to an outside address. The AI Employee raised it as an action needing approval. She read the request, thought it looked wrong, said no, and found the planted text in the original message within a minute. Nothing left the company. The log turned a five day investigation into a two minute one.

Risk five: the action cannot be undone

An email that reaches a customer cannot be recalled. A deleted record may be gone. A payment sent is a payment sent. These are the actions where after the fact detection is worth very little, because knowing about it does not fix it.

That is the entire reason for approval gates on send, spend, delete, and invite. Everything else in a safety setup helps you notice and recover. Only the gate stops the thing from happening, so it belongs exactly on the actions where recovery is not available.

Risk six: a compromised account brings the AI with it

If a teammate's account is taken over, whatever that account connected is now reachable by whoever took it. The AI Employee did nothing wrong. It is simply attached to an identity that is no longer in the right hands, which is the same problem as any other connected app.

Containment is unglamorous: two factor authentication on every account you connect, connections owned by a shared company account rather than a personal one where that is possible, and revoking connections the same day someone leaves. Add this to your offboarding checklist and it stops being a thought you have at midnight.

What goes wrongHow oftenWhat contains it
Too much permission grantedVery commonOne account, narrowest scope, widen only on need
Hidden instructions in contentUncommon but realApproval on anything leaving your company
Confidently wrong outputCommonReview before customer-facing, one trusted source of facts
No record of actionsCommon in weak toolsA full action log you can read yourself
Irreversible action takenRare with gates, likely withoutApproval on send, spend, delete, invite
Compromised teammate accountRareTwo factor auth, revoke on offboarding

Contain all six in one afternoon

  1. 1. List what the job truly needs — Write the job in a sentence, then grant only the accounts that sentence requires. Everything else stays disconnected.
  2. 2. Put the gate on the irreversible four — Send, spend, delete, and invite always ask you first. Do this before enabling any write access.
  3. 3. Find the log and bookmark it — Open it once so you know where it lives and what it shows. Ten minutes now saves a bad afternoon later.
  4. 4. Keep drafts under review for two weeks — This catches confidently wrong output while nothing is at stake.
  5. 5. Turn on two factor auth everywhere you connected — The AI connection is only as safe as the account it hangs off.
  6. 6. Add revoke to your offboarding list — When somebody leaves, their connections go the same day, alongside their email account.

FAQ

Has an AI ever been tricked into leaking data by content it read?

Yes, this has been demonstrated repeatedly by security researchers across many products, which is why we treat it as a live risk rather than a theoretical one. The defence is that instructions found inside content never carry your authority, and outbound actions still require your approval.

What is the worst realistic outcome of a read-only setup?

A wrong summary. Read-only means nothing is sent, changed, or deleted, so the failure stays inside your own screen. This is why we recommend starting there rather than trusting a setup you have not watched yet.

Can the AI change its own permissions?

No. Changing access, inviting users, and altering roles are gated actions that require a person. This matters because a system that can widen its own reach makes every other control temporary.

How would I even notice a problem?

Through the log and through approval prompts that look wrong. Reading the log weekly for the first month builds a sense of what normal looks like, which is what makes abnormal stand out later.

Is any of this unique to AI?

Four of the six apply to any connected app: over-broad permissions, missing logs, irreversible actions, and compromised accounts. What AI adds is speed and the hidden instruction problem, which is why the approval gate carries more weight here than it does with ordinary software.