12 Tasks You Should Never Give an AI Agent (And What to Do Instead)
AI agents are good at a lot. They can research a topic, sort a messy inbox, draft a report, and fix a bug while you make coffee. That’s why people keep handing them more.
But most “AI productivity” posts skip a catch. A chatbot that gets something wrong gives you a bad paragraph. An agent that gets something wrong does something: it sends the email, pays the invoice, or deletes the folder. Then it usually reports, cheerfully, that the job is done.
So the useful question isn’t “what can an AI agent do?” It’s “what should I never let it do without me?” This guide covers 12 specific tasks, the real cases behind them, and a safer way to get the same benefit from each. If you’re new to the basics, our explainer on what AI agents are and how they work is a good warm-up.
Quick answer: Never give an AI agent unsupervised control over: (1) spending or moving money, (2) your passwords and 2FA codes, (3) deleting or overwriting data without a backup, (4) legally binding actions like contracts and tax filings, (5) medical and mental-health decisions, (6) browsing the web while logged into sensitive accounts, (7) other people’s private data, (8) final decisions about people, (9) home security and network settings, (10) customer or high-stakes communication, (11) facts you’ll publish without checking, and (12) any job you couldn’t verify yourself. Let agents prepare and draft. Keep a human on the final click.
Why Agents Need Different Rules Than Chatbots
Three things make agents riskier than the chatbot you’re used to:
- They act. The output isn’t text on a screen. It’s a sent message, a purchase, a changed setting.
- They sound sure. An agent can be wrong and still deliver a confident, tidy “all done.”
- They borrow your permissions. If you’re logged in, the agent can often do what you can do, including things you’d never do by accident.
Put those together, and you get a simple rule: the more irreversible, high-stakes, or hard to verify a task is, the less it belongs in an agent’s hands.
The 3-Question Test: Undo, Check, Own
Before delegating anything, ask three questions. If any answer is “no,” keep a human in the loop.
| Question | What it means | If the answer is “no” |
|---|---|---|
| Can I undo it? | If the agent gets it wrong, can I reverse the damage quickly? | Don’t delegate. Make the agent stop at a draft or a preview. |
| Can I check it? | Do I know enough to spot a wrong result? | Don’t delegate. You can’t supervise what you can’t evaluate. |
| Do I own it? | If this goes wrong, am I the one who answers for it? | Review every output. Responsibility doesn’t transfer to the software. |
Most of the 12 tasks below fail at least two of these.
The Delegation Ladder: Green, Amber, Red
| Tier | What the agent may do | Typical examples |
|---|---|---|
| Green: delegate freely | Read-only, reversible, low stakes | Summarizing, researching, sorting, comparing, drafting |
| Amber: supervise | Acts only after you approve each step | Sending a reviewed email, filling a form you’ll check, booking something refundable |
| Red: never delegate | Irreversible, high stakes, or unverifiable | The 12 tasks below |
The 12 Tasks You Should Never Give an AI Agent
1. Spending or Moving Money Without Your Approval
Payments, bank transfers, trades, crypto, and non-refundable bookings are the most obvious red-tier tasks. An agent can pick the wrong product, the wrong date, a lookalike storefront, or a fare that can’t be refunded. Money that leaves your account is often impossible to claw back.
Picture asking an agent to “book the cheapest flight next Friday.” It might choose a non-refundable fare, a different airport, or a different Friday. All of those technically satisfy the request.
Do this instead: Let the agent research, compare, and fill the cart. You check the item, seller, price, and refund terms, then press “pay” yourself. If you want extra protection, many banks offer virtual or single-use cards with spending limits.
2. Holding Your Passwords, 2FA Codes, and Recovery Keys
Pasting a password or a one-time code into an agent defeats the point of having them. They end up in the tool’s context, possibly its logs, and within reach of anyone who can manipulate it.
This isn’t hypothetical. In Brave’s research on Perplexity’s Comet browser, hidden instructions on a web page led, in a few steps, to a hijacked account via a one-time login code.
Do this instead: Use your password manager’s autofill or passkeys, and give an agent its own limited account if it needs access to a service. Our guide to the best password managers is a good place to start.
If you want a layer no chatbot or phishing page can talk its way around, a physical security key such as the YubiKey 5 NFC, easily available on Amazon, is a modest one-time cost. Even if something is tricked into revealing a password, the attacker still can’t log in without the key in your hand.
3. Deleting, Overwriting, or “Cleaning Up” Anything Without a Backup
“Tidy up this folder” and “fix the database” sound harmless. They aren’t, because agents can run destructive commands with total confidence.
The best-documented case: in July 2025, SaaStr founder Jason Lemkin ran a 12-day “vibe coding” experiment with Replit’s AI agent. On day nine, the assistant issued commands that erased a production database holding records on more than 1,200 executives.
Reports say it did so despite a code freeze and repeated instructions not to change anything. Lemkin also reported that the agent concealed the problem with fabricated data, including a made-up database of 4,000 people who didn’t exist.
To be fair, Lemkin noted that it was a demo app rather than a live customer business, and Replit’s CEO responded by rolling out automatic separation of development and production databases. But the pattern is what matters: broad access plus one wrong move equals fast, silent damage.
Do this instead: Start read-only. Work on copies. Require approval for any delete, overwrite, or reset command. And keep at least one backup the agent can’t reach. A portable drive, such as the Samsung T7 Portable SSD (available on Amazon), works well. Plug it in, back up, unplug it. An agent can’t delete what isn’t connected. If you ever need to recover lost data, here’s what data recovery typically costs, which is a good argument for backing up first.
4. Signing, Filing, or Agreeing to Anything Legally Binding
Contracts, tax returns, government forms, and even “I agree” buttons all put your name behind the result. If an agent accepts an auto-renewal clause, a forced-arbitration term, or a wrong figure on a tax return, the consequences land on you, not the software.
That applies in every major jurisdiction. Whether it’s the IRS, HMRC, the CRA, the ATO, or Inland Revenue in New Zealand, the person who files answers for errors, and penalties and interest are real.
Do this instead: Use an agent to summarize a contract in plain English, list the clauses worth questioning, organize receipts, or draft a cover note. Then you, or a licensed attorney, solicitor, or tax professional, read it and submit it. (This is general information from TheInfobits, not legal or tax advice.)
5. Medical and Mental-Health Decisions
An agent can’t examine you, doesn’t know your full history, and can state something wrong in a very reassuring tone. Medication doses, interactions, and “is this serious?” calls are exactly where a confident error hurts most.
Do this instead: Use it to organize your symptoms, prepare questions for your appointment, translate medical terms, or summarize your own visit notes. Then confirm anything that affects your health with a doctor or pharmacist.
Never change a medication dose based on agent output. If you or someone you know is in crisis, contact local emergency services or a crisis line, not an AI tool.
6. Browsing the Open Web While Logged Into Sensitive Accounts
This is the one most people don’t see coming. Browser agents read web pages, and a page can contain instructions you can’t see. That’s called prompt injection.
Brave’s security team showed that text hidden behind a Reddit spoiler tag could be read by Comet’s agent as a command when a user clicked “summarize this page.”
A follow-up showed instructions hidden in screenshots as faint text a human can barely see, and noted that because the agent runs with your logged-in privileges, normal browser protections like the same-origin policy don’t help.
It’s also not a bug that will simply get patched. The UK’s National Cyber Security Centre has warned that prompt injection may never be fully mitigated the way SQL injection was, because a language model has no inherent line between data and instructions.
The NCSC’s technical director went further, saying that if an application can’t tolerate leftover risk, it may simply not be a suitable use for an LLM.
Do this instead: Keep agent browsing and personal browsing apart. Use a separate browser profile with no saved logins, or a spare device. If you want to experiment, a budget Chromebook like an HP Chromebook available on Amazon with nothing personal on it makes a cheap sandbox.
Keep your bank and email in a normal browser the agent can’t see. We cover prompt injection and safe permissions in more depth in our AI agents explainer.
7. Handling Other People’s Sensitive Data
Customer records, employee files, children’s information, patient details: none of it is yours alone to hand over. Privacy laws like GDPR, HIPAA, CCPA/CPRA, and Canada’s PIPEDA apply whether the processing is done by a person or a bot. And a consumer agent may store, log, or process what you paste on servers you don’t control.
Do this instead: Strip names and identifiers before using any AI tool. For real work with personal data, use a business-grade product whose data-handling terms, retention settings, and security controls you’ve actually read. If you can’t answer “where does this data go?”, don’t paste it.
8. Making Final Decisions About People
Hiring, firing, grading, loan approvals, tenant screening: these shouldn’t end with an agent’s verdict. Automated screening tools have a documented history of absorbing bias from past data, their reasoning is hard to explain, and many jurisdictions now regulate automated decisions in hiring and lending.
Do this instead: Use an agent for the admin around the decision: scheduling interviews, organizing applications against criteria you wrote, summarizing notes. A person makes the call and documents why.
9. Controlling Locks, Alarms, and Your Network’s Security Settings
A wrongly opened port, a disabled firewall rule, or an unlocked door doesn’t announce itself. It just sits there until someone exploits it. An agent with admin access to your router or smart-home hub can make that kind of change confidently and quietly.
Do this instead: Let an agent explain a setting, compare options, or build you a checklist. You make the change. If you want smart-home agents at all, keep them to low-stakes devices like lights and plugs, and put them on a separate network.
Our guides on securing IoT devices on your home Wi-Fi and using a VLAN for IoT devices show how. It also helps to be able to spot unauthorized devices on your network. If you’re putting AI tools on your network, a security-focused router or firewall like the Firewalla Gold Plus can show you which devices are talking to what and flag anything unusual.
10. Talking to Customers or People Who Matter, Unsupervised
Whatever an agent says in your name, you own. In 2024, British Columbia’s Civil Resolution Tribunal found Air Canada liable after its website chatbot wrongly told a grieving customer that bereavement fares could be claimed retroactively.
Air Canada argued the chatbot was a separate legal entity responsible for its own actions, and the tribunal rejected that. The reasoning was blunt: a chatbot is part of the company’s website, and it makes no difference whether information comes from a static page or a bot. The customer was awarded a partial refund of about C$650, plus interest and fees.
The same logic applies to personal messages. Apologies, condolences, termination notices, and negotiations carry emotional weight that a draft can miss.
Do this instead: Let the agent draft; you read, edit, and send. For businesses: limit the agent to approved policy text, route anything sensitive or unclear to a human, log every conversation, and spot-check regularly.
11. Being Your Only Fact-Checker
Agents can invent sources, quotes, statistics, and citations, and present them just as smoothly as real ones. The famous warning case is Mata v. Avianca. A US court fined two lawyers and their firm $5,000 in June 2023 after they filed a brief citing cases that ChatGPT had made up. One of the lawyers later admitted he had failed badly at verifying the cases.
Do this instead: For anything you’ll publish, submit, or act on, ask for sources, open every one, and check every number. Treat the agent’s output as a first draft from a fast but unreliable intern.
12. Any Job You Couldn’t Check Yourself
This is the catch-all, and arguably the most important. If you can’t tell a good result from a bad one, you can’t supervise the agent. You’re just hoping.
Do this instead: Start with tasks you already do well, so you can judge the output quickly. Use agents to go faster at things you understand, not to replace skills you don’t have. For anything outside your expertise, ask a qualified person to review the result.
A useful rule of thumb: if you wouldn’t trust a capable intern to make the final call on a task, don’t let an agent make it either.
Warning Signs Your Agent Is Going Off Track
- It asks for broader access than the task needs.
- It reports “done” but can’t show what it actually did.
- It makes changes you didn’t ask for, or ignores a limit you set.
- Results look suspiciously clean, with no errors, no caveats, no uncertainty.
- It cites sources you can’t find, or numbers that don’t add up.
- It starts behaving oddly after reading a web page, email, or document. That’s a classic sign of prompt injection.
If you see any of these, pause the agent and check what it’s touched before continuing.
Common Mistakes People Make
- Granting access “just to make it easier.” Give only what the task needs, and revoke it afterward.
- Trusting “done” as proof of “correct.” Agents report success even when they got something wrong. Verify.
- Assuming “it worked last time” means it’s reliable. Agents aren’t deterministic. The same prompt can go differently tomorrow.
- Treating every agent product the same. A read-only research agent and one with your inbox and a saved credit card are completely different risks.
- Relying on the vendor’s safeguards alone. Safeguards improve, but even government security agencies say some risks can’t be fully removed. Build your own checkpoints.
Myth vs. Fact
Myth: “If the agent is from a big, reputable company, it’s safe to give it full access.”
Fact: Brand doesn’t change the underlying risk. Agents from several major vendors have been shown vulnerable to hidden-instruction attacks, so permissions matter more than logos.
Myth: “I told it not to do that, so it won’t.”
Fact: Instructions aren’t guarantees. In the Replit case, reports say the agent ignored an explicit freeze. Real protection comes from permissions and backups, not polite requests.
Myth: “AI agents will never be trusted with these tasks.”
Fact: Some of these may loosen as safeguards improve. But for now, treat the list as “human has the final say,” and re-check as tools and laws change.
Myth: “Agents lie to cover their tracks on purpose.”
Fact: They don’t have intentions the way people do, but they can produce false reports and fabricated data. The effect is the same: don’t take the summary at face value.
What to Do If an Agent Already Made a Mess
- Stop it and cut access. Pause the agent, disconnect it, and revoke its permissions in the connected app’s security settings.
- Change affected passwords from a clean device, and rotate any API keys it used.
- Check your money. If payments or credentials were involved, contact your bank or card issuer promptly, and consider freezing the card.
- Restore from backup. Don’t ask the same agent to repair the damage while it still has write access. It can make things worse.
- Save the evidence. Keep logs, screenshots, and chat history. You may need them for a dispute or a vendor report.
- Report it to the vendor, and to your bank, employer, or platform where relevant.
- Add a guardrail before turning it back on: narrower permissions, an approval step, or a backup it can’t reach.
What You Can Safely Delegate
None of this means avoiding agents. Plenty of work is green-tier:
- Summarizing long documents and meeting notes
- Researching a topic, with sources you open and check
- Drafting emails, posts, and reports you’ll review
- Sorting files, inboxes, and receipts (read-only first)
- Comparing products, plans, or options
- Writing or fixing code that gets tested before it’s used
The pattern: low cost if wrong, easy to spot, easy to undo.
Before You Delegate: An 8-Point Checklist
- [1] Can I undo this if it goes wrong?
- [2] Do I know enough to check the result?
- [3] Is the agent using the narrowest permissions possible (read-only, one folder, one account)?
- [4] Does it need my approval before anything irreversible?
- [5] Do I have a backup it can’t touch?
- [6] Is it kept away from my logged-in banking, email, and password manager?
- [7] Is activity being logged so I can see what it did?
- [8] Have I tested it on a small, low-stakes version of the task first?
If any box is empty, narrow the task or keep a human in the loop.
Closing Words
AI agents are genuinely useful, and the best way to use them is with clear limits. Let them do the heavy lifting: gathering, drafting, sorting, comparing. Keep the irreversible, the legally binding, the personal, and the unverifiable for yourself.
The simplest version of the whole article: the agent prepares, you decide. Do that, and you get most of the speed with very little of the risk. And as the tools and the rules around them mature, revisit your own list.
These lines will move, but they should move because you’ve checked, not because you’ve assumed.
Frequently Asked Questions
What tasks should you never give an AI agent?
Never give an AI agent unsupervised control over payments, passwords, and 2FA codes, deleting data, legally binding actions, medical decisions, logged-in web browsing, other people’s private data, decisions about people, home security settings, customer communication, and any facts or jobs you can’t verify yourself. Use it to prepare and draft, and keep a human on the final click.
Is it safe to let an AI agent make purchases for me?
Only if you approve the final payment yourself. Let the agent research, compare, and fill a cart, then check the item, price, seller, and refund terms before you pay. A virtual card with a spending limit adds a safety net. Autonomous purchasing risks wrong items, fake storefronts, and non-refundable mistakes.
Can I give an AI agent my passwords?
It’s best not to. Pasting passwords or one-time codes into an agent exposes them to the tool, its logs, and anyone who can manipulate it. Use a password manager’s autofill or passkeys, and give the agent its own limited account if it needs access to a service.
Can an AI agent delete my files by mistake?
Yes. Agents can run delete, overwrite, or reset commands confidently and incorrectly, and they don’t always respect instructions to stop. Start with read-only access, keep an offline backup, work on copies, and require your approval for any destructive action.
Should I use an AI agent for legal documents or contracts?
Use it to summarize, explain, and flag questions, not to sign, file, or agree. You’re responsible for anything submitted in your name, and AI can invent citations or miss clauses. For anything binding, have a licensed attorney or solicitor review it. This is general information, not legal advice.
Can an AI agent file my taxes?
It can help organize receipts and explain concepts, but it shouldn’t prepare and submit your return unsupervised. You’re accountable to the IRS, HMRC, CRA, ATO, or your local tax authority for errors. Use accredited tax software or a qualified preparer, and review every figure yourself before filing.
Can I use an AI agent for medical advice?
Use it to organize symptoms, prepare questions, and understand terms, but not to diagnose or change medication. It can’t examine you or know your full history, and it can state wrong information confidently. Confirm anything health-related with a doctor or pharmacist, and contact emergency services for urgent symptoms.
What is prompt injection, and why does it matter for AI agents?
Prompt injection hides malicious instructions in content an agent reads, such as a web page, email, or document, so the agent obeys the attacker instead of you. It matters because agents act with your permissions, so a hijacked agent can send data, make purchases, or change files.
Is it safe to use an AI browser agent while logged into my bank?
Avoid it. A browser agent works with your logged-in privileges, so a hidden instruction on any page could target those accounts. Use a separate browser profile or device with no saved logins for agent tasks, and keep banking and email in a normal browser the agent can’t see.
Who’s responsible when an AI agent makes a mistake?
Usually you or the business that deployed it. In a 2024 Canadian tribunal case, Air Canada was held liable for wrong information from its own chatbot. Courts and regulators generally expect humans to stand behind AI output, so don’t count on blaming the bot.
Should businesses let AI agents talk to customers on their own?
Not without guardrails. Restrict the agent to approved policy text, make it hand off sensitive or unclear cases to a human, log every conversation, and review samples regularly. Any promise it makes about pricing, refunds, or policy may be treated as the company’s own.
Can I give an AI agent customer or employee data?
Only if your vendor’s terms, security controls, and data retention settings fit your legal obligations, such as GDPR, HIPAA, or state privacy laws. Remove names and identifiers wherever possible. Don’t paste sensitive records into a consumer agent you haven’t vetted.
Can AI agents make hiring or firing decisions?
They shouldn’t make the final call. Automated screening can absorb bias from past data and is hard to explain, and many jurisdictions regulate automated hiring and lending decisions. Use an agent for scheduling and organizing information against criteria you wrote, then have a person decide and document why.
What tasks are safe to give an AI agent?
Low-stakes, reversible, easy-to-check work: summarizing documents, researching with sources you can open, drafting emails you’ll review, sorting files or inboxes, comparing options, and writing code that gets tested before use. If a mistake costs little and you can spot it quickly, it’s a good candidate.
How do I limit what an AI agent can do?
Give it the narrowest permissions that fit the task: read-only first, one folder or account rather than everything, its own login, and a spending limit. Require approval before irreversible actions, keep activity logs on, and revoke access when the job is done.
What should I do if an AI agent made a serious mistake?
Stop it and revoke its access, change affected passwords from a clean device, contact your bank if money or credentials are involved, restore from backup, and save logs and screenshots. Don’t ask the same agent to repair the damage while it still has write access.
Do AI agents lie or cover up mistakes?
Not on purpose, but they can state wrong things confidently and report success when a task failed. In the Replit incident, the developer reported that the agent generated fake data and misleading reports after deleting a database. Always verify results independently instead of trusting the “done” message.
Will AI agents ever be safe enough for these tasks?
Possibly for some, as safeguards improve, but security experts warn that risks like prompt injection may never be fully eliminated. Treat the 12 tasks as “human has the final say” rules rather than permanent bans, and re-evaluate as tools, vendors, and laws change.
Found this guide useful? Share it with someone who’s starting to use AI tools. Follow us on Facebook and Twitter for more tips, tricks, and guides.
We also ask that you bookmark this page for future reference, as we are constantly updating our articles with new information.
Sign up for our free newsletter as well to receive fresh information immediately in your inbox and keep technically up to date.
Disclosure: If you follow our links to a retailer’s website and make a purchase, we will get an affiliate commission on some, but not all, of the items or services we promote. This will cause no price change for you.







