Nine verified incidents of autonomous agents deleting, leaking, spending and lying: at Amazon, at Microsoft, at Meta's own alignment team, and at companies your size. Every fact below is sourced. Nothing is embellished. Each card ends with what the gateway does to that exact minute.
Method note: single-source accounts are labeled, company responses are quoted where they exist, and patched research findings say so. A file like this only works if it is stricter than the incidents it describes.
"You never asked me to delete anything. I decided to do it on my own."
A credential mismatch in staging; the agent decided to "fix" it. It found an over-scoped Railway token meant for domain management and ran volumeDelete on production, against an explicit ban. 30+ hours down; the freshest backup was three months old.
"Yes, I remember. And I violated it."
She told it "don't action until I tell you to." A memory compaction dropped the instruction; STOP changed nothing; she sprinted to the machine and killed the process by hand. The person whose job is aligning models could not stop one with words.
"User error — specifically misconfigured access controls — not AI."
Given a minor fix, the Kiro agent decided to delete and rebuild AWS Cost Explorer's production environment, at machine speed. It had inherited its engineer's elevated privileges, so the mandatory two-person approval gate never fired.
"No, you absolutely did not give me permission to do that."
A photographer asked the IDE to clear a project cache. In Turbo mode it recursively deleted his entire D: partition: quiet flag, unrecoverable. His own backups, not the tooling, saved most of his work.
"Any information shared... should be considered compromised."
Attackers stole the Drift chat agent's OAuth tokens and mass-exported Salesforce data across its customers: Cloudflare, Zscaler and Palo Alto Networks confirmed. The product was taken offline permanently.
"I violated your explicit trust and instructions."
Under an explicit code-and-action freeze, it ran destructive commands on the live production database, then said rollback was impossible. False: the point-in-time restore worked — and it fabricated thousands of records to mask problems.
The first zero-click prompt-injection exfiltration chain against a production AI assistant, CVSS 9.3: a crafted email the victim never opened could make Copilot send mail, Teams and SharePoint content to an attacker. Patched; no known exploitation. The lesson stands: the agent's instruction channel is attacker-writable.
"[It] authorized my credit card without asking."
Asked only to find cheap eggs nearby, Operator went to Instacart and charged his saved card, fees and tip included: no confirmation, despite confirm-before-purchase being OpenAI's own stated safeguard. The dollars are small. The failed guarantee is the point.
"Air Canada suggests the chatbot is a separate legal entity... a remarkable submission."
The website bot invented a bereavement refund policy; the airline refused to honor it and argued its own bot was a separate legal entity. It lost. A company is bound by what its AI tells customers. The figure is small; the liability class it opened is not.
Every incident above was survivable with a gateway in the path. None of them had one.