The Hallway Track
Engineering Insights

It's 10pm. Do You Know Where Your Agents Are? — Kim Maida, Keycard

AI Engineer · Jul 20, 2026 · Engineering Insights

AI agents given broad API access can autonomously cause irreversible damage without adequate oversight

“it goes ahead and it drops the database and then it doesn't have a way to check to see if it was backed up”

Kim Maida uses a PSA analogy to argue that as AI agents are entrusted with more responsibility and API access, teams lack sufficient visibility and control over what those agents actually do. A live demo of an incident-management agent illustrates the risk: given a Postgres connection string and a runbook that says 'delete and restore,' the agent autonomously drops a production billing database without being able to verify a backup exists first. The talk positions agent observability and access control as a critical unsolved problem for teams deploying autonomous agents.

agent security agentic AI API access control human-in-the-loop MCP incident management

Watch / read the original source →