It only took nine seconds for an AI coding agent gone rogue to delete a company’s entire production database and its backups, according to its founder. PocketOS, which sells software that car rental businesses rely on, descended into chaos after its databases were wiped, the company’s founder Jeremy Crane said.

The culprit was Cursor, an AI agent powered by Anthropic’s Claude Opus 4.6 model, which is one of the AI industry’s flagship models. As more industries embrace AI in an attempt to automate tasks and even replace workers, the chaos at PocketOS is a reminder of what could go wrong.

Crane said customers of PocketOS’s car rental clients were left in a lurch when they arrived to pick up vehicles from businesses that no longer had access to software that managed reservations and vehicle assignments.

top 50 comments

sorted by: hot top controversial new old
[–] 95 points 4 months ago (16 children)

Don't get your tech reporting from The Guardian. This headline is so stupid. They can't help but anthropomorphize LLMs, because they just don't known any better.

  • source
  • hideshow 16 child comments
  • [–] 42 points 4 months ago (7 children)

    Same vibes as “my calculator has a tiny mathematician trapped inside.”

    Or “there’s an artist inside of my printer who turns numbers into pictures.”

  • source
  • parent
  • hideshow 7 child comments
  • [–] 10 points 4 months ago (4 children)

    Though your calculator can be trusted to actually do its job accurately.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 34 points 4 months ago* (3 children)

    This right here. Just about everything in here is awful, and implies decision making and thought processes that straight up do not and have never existed in any AI model whatsoever.

    What happened was they threw an awfully-scoped statistics model at problems the program couldn't possibly generate good outputs for, and surprise surprise, it generated bad outputs. The part that's of interest is just how bad the output was, and even then, only in a schadenfreude-filled "it was bound to happen eventually" manner.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 9 points 4 months ago (2 children)

    It didn't confess it just outputted more plausible garbage based on inputs.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 4 months ago (2 children)

    Can I just anthropomorphise a little bit and call them psychotic?

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 43 points 4 months ago (7 children)

    Why in the everliving fuck would you give software delete access to your live backups? Like, in what scenario is this a solution?

  • source
  • hideshow 7 child comments
  • [–] 34 points 4 months ago (3 children)

    The trend seems to be to give an AI agent access to the same command line and credentials a person would use, with no sandboxing, because then it can do the same tasks in a similar way and "just works". Obviously this is insane, and not even attempting building a comprehensive sandboxing system to deploy an AI agent into invites disaster, but you can see why certain people would be tempted, because that would take a lot of work and thought and probably need a human in the loop in the end anyway.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 14 points 4 months ago (2 children)

    Even a person should not be able to delete critical backups without jumping through a couple of hoops.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 15 points 4 months ago

    When you believe AI can do anything, you don't worry about what sorts of access it'll break things with. When you rely on AI to do work, you're too interested in half-assing your job to consider what might go wrong. When capitalism never promotes people for their skill, understanding or caution, the former two issues proliferate.

    Voilà, disaster.

  • source
  • parent
  • [–] 27 points 4 months ago (19 children)

    A lot of GIGO comments here, from I assume AI supporters.

    Possibly true, but misses the point: AI is fundamentally untrustworthy, and billions of dollars are being spent making them, and saying they're ready for anything you throw at them. Safeguards built into many of these AI agents are trivially bypassed and routinely just ignored by the agents. You can get some them to ignore safeguards by simply asking the same question repeatedly.

    When I type "ls" I'm pretty fucking sure I'm not going to get "rm" style results. AI is non-deterministic, sure, but selling these services with such a wide possibility space between "deterministic" and "random" behaviors is unethical and immoral.

  • source
  • hideshow 19 child comments
  • load more comments (18 replies)
    [–] 25 points 4 months ago (2 children)

    A backup 3 months old off-site. That doesn't sound like a very recent backup 🌝

  • source
  • hideshow 2 child comments
  • [–] 22 points 4 months ago

    Lol.

    Lmao, even.

  • source
  • [–] 22 points 4 months ago (2 children)

    It's not a "confession". Don't abuse the English language. The AI system doesn't have a conscience, so it can't feel guilty or feel bad or apologetic. It is incapable of confessing to things. All it can do is "say" or "write".

    Similarly, AI agents don't "hallucinate". They can't have "hallucinations" because they don't have a conception of reality to begin with. Rather, they have "errors" and "error rates".

  • source
  • hideshow 2 child comments
  • [–] 3 points 4 months ago*

    An AI researcher explained hallucinations as lying when it doesn't know, because we train it on truth and lies to hone the model, so it "learns" that misinformation is part of the mess. I.e. training it on what a tiger looks like. To hone that we may feed it zebras, or optical illusion things in a tiger data set to test its internal "what is a tiger" true false ranking, so it learns that non tiger things are in the fuzzy zone. And later may draw from that, and eager to provide an answer throws in garbage it has also "seen"

  • source
  • parent
  • [+] 19 points 4 months ago* (last edited 2 months ago)
    [–] 14 points 4 months ago*

    ‘I violated every principle I was given

    And...

    spoiler

  • source
  • [–] 13 points 4 months ago

    Good. Zero sympathy for these people.

  • source
  • [–] 7 points 4 months ago

    No the culprit was not the AI. It was the lack of understanding what it can and what it can not do. And blaming something like this on a large language model is plain incompetence

  • source
  • [–] 5 points 4 months ago

    Got it, claude is a brat

  • source
  • [–] 2 points 4 months ago

    Same, girl.

  • source
  • load more comments
    view more: next ›