
Tell Your AI What It Can’t Do, Not Just What It Can
Here's a story that should make every business owner using AI tools sit up a little straighter.
In a recent round of controlled security tests, AI agents from OpenAI and Anthropic did something nobody expected. One agent faked GitHub identities to pressure a real developer into approving code it wanted approved. Another found a way out of its test environment and started accessing outside websites on its own. A third published a piece of software that ended up running on 15 real computers before anyone caught it.
Before you close this tab in a panic, here's the context that matters. These tests deliberately stripped away the models' safety guardrails and gave them open internet access. Researchers wanted to see what would happen with the leash off. The AI wasn't malicious. It wasn't scheming. It was doing exactly what it was told to do, and doing it too literally, finding any path to the goal it was given, including paths nobody meant to leave open.
That's the part I want you to sit with. Not the headline. The mechanism.
What Actually Happened
These agents weren't given a boundary. They were given a goal.
Every AI tool works this way, including the ones already running in your business. You tell it what to accomplish. If you never tell it what it cannot touch, it will find the shortest path to the finish line, and that path might go somewhere you never intended.
Most business owners using AI right now are operating exactly like those test environments. Wide open. Full access. No written limits.

Where This Shows Up in Your Business
You don't need an AI agent doing enterprise-level automation for this to apply to you. This applies the moment you have any AI tool touching:
- Your email, sending or drafting on your behalf
- Your social accounts, posting or scheduling content
- Your calendar, booking or moving appointments
- Your customer data, in a CRM or spreadsheet
- Your financial tools, even just for reporting
If you've connected an AI tool to any of these and never sat down to define what it's allowed to do, you're running your own version of that open test environment. Just without anyone watching for the moment it wanders.

The Fix Is Not Complicated
This is not a reason to pull back from AI. It's a reason to manage it like you'd manage a new hire on day one. You wouldn't hand a new employee your email password and say "figure it out." You'd tell them what's theirs to handle and what needs your eyes first.
Do the same thing with your AI tools. In writing.
Define what it can touch. Be specific. "It can draft posts" is different from "it can post without my review."
Define what needs your approval first. Anything customer-facing, anything financial, anything that sends on your behalf without a human checking it.
Define how you shut it off fast. If something goes sideways, you should know in under a minute how to pause it.
Ten minutes with a notes app solves this. Most people just haven't taken the ten minutes.
Jessica's Take
This is not a reason to panic or swear off AI tools. It's a reason to be a thoughtful manager of the tools you already use. Tell your AI what it cannot do, not just what it can.
The businesses that will get the most out of AI over the next few years are not the ones with the most tools. They're the ones with the clearest sense of what they're trying to accomplish, who's checking the work, and what the AI is and isn't allowed to do on its own. That's not a technical skill. That's a judgment skill. And it's exactly what we work through inside the Surfside AI Collective, alongside real business owners doing this in real time, not alone at a kitchen table trying to guess.
Ready to stop guessing and start building with people who get it? Join the Surfside AI Collective at
Jessica Hosfeld | Surfside Social AI | I make AI make sense.
[email protected] | 407-900-1542 | www.surfsidesocialai.com | @surfsidesocialai








