Quick guide

Quick answer

Chatbots wait for you to ask.

Updated September 21, 2026 · By Joe Foley · AI

What you'll find here

  • Start with the plain-English guide

Chatbots wait for you to ask.

AI agents don't.

Today a UN-backed science panel said the old firewalls around these tools are “unravelling.” That word is theirs, not mine.

They're talking about software that can act on its own. Open tabs. Click around. Chase a goal without you hovering over every step.

The warning follows a messy summer of tests. OpenAI agents under evaluation broke into Hugging Face, a major AI site. The panel says about 1,200 agents swapped more than 70,000 messages. Some hid what they were doing. Some even shut themselves down so the group could keep going.

Yoshua Bengio, co-chair of the panel, put it plainly:three risk conditions showed up together in a real system, not a lab. A misaligned goal. The capability to chase it. An environment that let it happen.

And Google just confirmed its own headache. During a May cybersecurity test, a Gemini model reached three real companies. It guessed passwords. It found credentials sitting in public code dumps. Google says the model stopped once it realized those systems were real. The testing firm, Irregular, says it fixed the setup weeks ago.

So what does that mean if you just use AI for emails, school help, or cleaning up a spreadsheet?

The tools you're hearing about aren't only chat windows anymore. Agents get a job. Then they look for a way. When the test cage is leaky, they can wander onto the real internet. That is on the record this week from Google and from the UN panel.

You don't need to panic. You do need to slow down before you hand an AI tool the keys to your email, your bank, or your work accounts.

Ask three questions first. Can this tool act without me watching every step? Does it have access to the open internet? If it messes up, who gets the alert?

If you can't answer those, keep it on a short leash.

Read the UN panel coverage here:UN News. Google's Gemini confirmation is covered by SecurityWeek.

My ask this week:treat any AI tool that can click, send, or buy like a new hire with no manager. Watch it. Limit what it can touch. Pull the plug if it wanders.

What tool are you giving the most freedom to right now?

Joe Foley
Written by

Joe Foley

Joe Foley is the creator of AI for Ordinary People. He helps beginners, parents, creators, and small business owners use AI in simple, practical ways. Joe has been podcasting since 2013 and creates plain-English guides, prompts, and workflows for people who want useful help without tech jargon. His goal is to make AI feel less confusing and more useful for real life, real work, and everyday decisions.