Home » Articles » When the Bot Can Act Without You — and How You Stop It

When the Bot Can Act Without You — and How You Stop It

What this means

AI actors are great at boring work — until something goes wrong. Spot trouble early, cut access fast, and protect email, banking, and money.

When the bot can act — kill-switch

Note: This site may show light ads and occasional affiliate links. How that works.

In AI advisor or AI actor we drew a line: an advisor is the agony aunt — a helper that suggests fixes, drafts, and second opinions. An actor gets things done: sends, clicks, files, books, deploys.

Actors are brilliant at boring work. They are also the tools that need a kill-switch — before you need it. When an actor goes wrong, or a bad actor steers the access you granted, “I will sort it later” can mean locked email, a bank you cannot reach, and money already moved.

If you cannot say in one sentence how you would stop this tool in under five minutes, do not give it mail, money, or admin power.


What “kill” actually means

A kill-switch is not a red cartoon button. It is a short list of moves you can do under stress:

  • Stop the run — cancel the agent job, pause the automation, close the unsupervised session.
  • Revoke access — disconnect the app in Google, Microsoft, or Apple “connected apps”; delete app passwords; remove browser-agent or plugin permissions.
  • Sign out other sessions — email and banking “devices” lists; end anything you do not recognise.
  • Rotate what was exposed — update passwords for accounts the actor could reach; turn on or tighten multi-factor authentication (mfa).
  • Disable the helpful shortcuts — inbox rules, forwarding, payment automations, deploy hooks you no longer want live.

Write down where those screens live while you are calm. Searching for “connected apps” for the first time during a scare wastes the minutes that matter. Keep that note where the team can find it — not only inside the AI chat that might be part of the problem.

How you will know before it is too late

You will not always get a dramatic alert. Watch for quiet tells:

  • Sends, invites, or invoice replies you did not approve
  • MFA prompts or login alerts you did not start
  • Email filters, forwarding, or signature changes you did not make
  • Bank or accounting “new payee,” “new device,” or unusual spend notices
  • Drafts going live, or a tool reporting success on a job you never asked for

Stop! Pause! Before you tap Approve on an unexpected login or payment prompt: Is it urgent? Do you know who it is from? Is it really from them? Deny first, investigate second. Approving “just to make it stop” can hand someone a session.

Also watch for politeness. Actors often fail in fluent language: “I have updated the supplier details as discussed,” when nobody discussed it. Fluency is not proof.

When “helping” outruns you

A calm afternoon. You connect an actor to email and a payments folder so it can “chase invoices and tidy admin.” It feels like hiring a careful junior who never sleeps.

By evening there are login alerts from a city you are not in. A forwarding rule you do not remember. A supplier chasing a payment that went to new bank details “confirmed” in a thread you barely skimmed. You open webmail — and the password you trust no longer works. The banking app wants a recovery path that now routes through the email you just lost.

Maybe it was a rushed permission. Maybe it was a bad actor using the door you opened. The lesson is the same: the blast radius — how much damage if it goes wrong — was not one wrong draft. It was identity: mail, money, and the recovery paths that tie them together.

Before you grant power

  • Start actors in draft-only or suggest-only mode.
  • Keep a human confirm on anything that spends, sends externally, or changes payee details.
  • Prefer number-matching mfa (or passkeys) so a random Approve tap is not enough.
  • Verify bank-detail changes on a number you already trust — never only inside the AI thread.
  • Once a month, open connected apps and sessions for email and finance accounts; remove stale access.
  • Keep a second recovery channel for banking that does not depend on the same mailbox the actor can touch.

Five minutes that prevent a bad week

  • Minute 1–2: Open connected apps for your main email. Remove anything you do not recognise.
  • Minute 3: Check forwarding and filters.
  • Minute 4: Open sessions or devices on email (and banking if you use an app). Sign out strangers.
  • Minute 5: Write the kill path for your most powerful AI connector on a sticky note or shared doc.

That is not paranoia. It is the same discipline as knowing where the fire extinguisher is before the toast burns.

A self-check

Name the most powerful AI connector you use — the one that can send mail or touch money. Can you say in one sentence how you would disconnect it in five minutes? If not, that is today’s job before you let it run unsupervised again.

Related: AI advisor or AI actor · If someone else is steering your AI · When automation keeps going · AI, human risk & scams