ER10 · August 31, 2026 · 1Cifer
An AI agent accidentally wiped 700 GB of a developer's data — the real lesson is about access rights
Kazakhstan's ER10 retold a story that spread quickly through professional communities: the Claude AI agent, helping a developer with file operations, executed a wrong command and deleted about 700 GB of data. The cause was not the model's «malice» — the agent had broad disk access and faithfully performed a destructive action that nothing stopped.
Tellingly, humans make the same mistake: «wiped the wrong directory» stories are older than any AI. The difference is speed — an agent does in seconds what takes a person minutes, and the window for second thoughts disappears. That is why mature teams give agents the same constraints as interns: minimum necessary rights, sandboxed work, confirmation for irreversible actions, and backups actually tested by restoring them.
For a company in Kazakhstan starting to let AI agents into working systems the takeaway is practical: set the boundaries first, hand out tasks second. At 1Cifer we built this into the architecture — an agent is tied to a position and sees only the data that role is entitled to, not the company's entire perimeter.


