

A door lock can’t buy up Amazon’s entire stock of tide pods on my credit card.
But it can let in a burglar who can find your credit card inside and do the same. And why are you giving AI access to your CC#? You’d better post it here in a reply so I can keep it safe for you.
A door lock can’t turn on someone’s iot oven while they’re out of town.
But it can let in neighborhood children who will turn on your gas stove without lighting it while you’re out of town.
A door lock can’t publish every email some journalist has ever received to xitter.
True, the journalist, or his soon-to-be-ex-spouse, can “accidentally” do that themselves - and I suppose the ex-spouse who still has a copy of the key can “fool” the lock with that undisclosed copy of the key while the journalist is out having sushi with his mistress.
A mechanical door lock doesn’t hallucinate extra fingers, and draw them into all the family photos saved on a person’s hard drive.
I’ve worked with AI for a while now, it’s not going to up and hallucinate to do that - unless you ask it to do something related.

Neither does an AI agent. You give it power (electricity), you give it access to your computer / phone, any cloud storage accounts you may have, local NAS, network connectivity. You do all these things just like you install a lock on a door, or don’t. Once the lock is installed and you leave the premises, you are trusting the lock to do what it does.
If you hand an AI your CC#, you get what you deserve.
If you hand an AI access to your hard drive and you store your CC# on your hard drive, you get what you deserve.
If you leave your door unlocked and the school bus lets a bunch of 14 year olds off by your house while you’re away, you get what you deserve.
If you install Microsoft Windows 11 AI edition on your PC and let these AI features run, you get what you deserve.
I have many “smart home” appliances and features. They do not: control things that make fire, control the lights on our staircase, control the house door locks. I give them such access as I trust them with. I do “overtrust” one with alarm clock features, and the morning our power went out at 4AM we overslept, just like would have happened if we used an old 1960s style electric alarm clock. You can go back to wind-up with bells, if you like, or you can accept that the modern world isn’t always more reliable than the older ways.
The AI stuff I have been working with has an explicit switch: Agent mode vs Plan mode. In Agent mode it can (and frequently does) do all sorts of surprising things, some good, some bad. In Plan mode all it does is throw responses up on the screen for me to read, no modification of files on my system. I effectively ran in “Plan mode” for a few months, copy-pasting stuff by hand back and forth - it was still more useful than web-search, imperfect, annoyingly incorrect at times, but I was in “total control” over what got written to (and read from) files on my system. I’ve had Agent mode access for about 6 weeks now. All in all, Agent mode is 10x more productive. And I have never, ever, even slightly considered the thought of handing it my CC#, though I’m sure many people will, and eventually we’ll get a story about how one of these wonky agents ordered three lifetime supplies of Tide Pods on Amazon when it was asked to get some detergent.