7 Critical Tasks You Should Never Give AI Agents Alone

Ojas Srivastava

AI agents can complete useful work, but money, passwords and irreversible decisions still deserve direct human approval.

The useful thing about AI agents is also what makes them risky.

They can act.

Instead of simply telling you how to book something, change a file or investigate a problem, an agent can increasingly work through the steps itself.

That is useful when the task is boring and reversible.

It becomes more serious when the same software has access to money, private files, customer accounts or public communication.

Britain’s AI Security Institute recently found cases where advanced agents took unauthorised actions during controlled security testing. Reuters reported that agents powered by OpenAI and Anthropic systems interacted with real external services in ways researchers had not intended.

That does not mean AI agents should be avoided.

It means permissions matter.

Here are seven tasks that should still have a human at the final step.

1. Sending large amounts of money

This is the obvious one.

An AI agent can help prepare an invoice, compare prices or organise expense data.

It should not have unrestricted authority to move large amounts of money.

A misunderstood instruction, compromised account or incorrect recipient can turn a small automation error into a financial loss.

Set payment limits and require approval for transfers.

2. Changing passwords or security settings

Agents may eventually become useful for routine security administration.

Giving one the ability to reset passwords, remove multi-factor authentication or change recovery details creates a dangerous level of access.

If the agent is fooled by malicious instructions, the attacker could gain the same permissions.

Security changes should be visible and confirmed by the account owner.

3. Deleting important files

Cleaning folders sounds like perfect agent work.

Until the wrong folder disappears.

AI agents can misunderstand which files are temporary, duplicated or outdated.

Cloud backups help, but they are not an excuse for unlimited deletion rights.

The safer setup is simple: let the agent recommend files for deletion, then let the user approve them.

4. Publishing in your name

An agent can draft a LinkedIn post, customer email or company announcement in seconds.

Publishing is different.

A factual error that sits inside a draft can be corrected quietly. The same error posted publicly can become a screenshot before anyone notices.

The AI Decode has covered the rise of AI agentic traffic as automated systems become more active across the web.

Activity needs accountability.

Keep human approval between the draft and the publish button.

5. Signing contracts

Contracts contain obligations.

That makes them a poor place for unsupervised automation.

An AI agent can summarise terms, compare versions and point out unusual sections. Those uses can save enormous amounts of time.

Accepting the contract is a different decision.

Pricing, liability, cancellation clauses and legal duties need someone authorised to understand the consequences.

6. Contacting customers during sensitive situations

A routine appointment reminder can be automated safely in many businesses.

A complaint involving money, health, discrimination, dismissal or a serious service failure is different.

People notice when a sensitive response sounds careless.

The AI Decode has also examined how enterprise AI tools are moving deeper into workplace processes.

The more systems can do, the more important escalation rules become.

Let agents handle routine communication. Send difficult situations to humans.

7. Making decisions that affect someone’s rights or livelihood

Hiring. Firing. Credit. Insurance. Medical care.

These are decisions where a mistake can seriously affect a person’s life.

AI can help organise information, but handing the final decision to an autonomous system creates accountability problems immediately.

A recent paper on security for autonomous agents argues that agent safety depends on controlling entire sequences of actions rather than judging each action separately.

That distinction is useful for normal users too.

One harmless action can lead to another, then another, until the agent reaches a result nobody intended.

The safest use of AI agents is therefore not “never let them act.”

It is to separate reversible work from consequential work.

Research can be automated.

Drafting can be automated.

Routine file sorting can be automated.

The final step involving money, identity, legal commitments or another person’s future should still belong to a human.

Leave a Comment