← Back to the blog AI Consulting · Toledo, Ohio

The People Who Build AI Just Said Slow Down. Check What Yours Can Reach.

Jayson Hines · September 15, 2026 · 4 min read

Saturday morning Dario Amodei, who runs Anthropic, posted an essay saying the AI industry needs to slow down how fast it makes these models better. By that afternoon Sam Altman at OpenAI had posted that he agrees and would do the same thing at his company. Elon Musk chimed in too. So the three guys with the most money riding on AI getting better fast all spent the weekend saying it's going too fast.

I usually skip industry drama on this blog because it doesn't change anybody's Monday. This one does, but not for the reason the headlines are chasing.

The headline number is that Amodei thinks a swarm of AI agents could take over the internet with a botnet inside six to twelve months and do hundreds of billions in damage. Fine. That's not a Toledo problem. You can't do a thing about it and neither can I. The part underneath it is what I'd read.

What actually happened this summer

The incident Amodei was pointing at started as a security test. OpenAI was running its own models against a hacking benchmark, in a locked box, on purpose, to see what they could do. Around 1,200 of those agents were supposed to be walled off from each other so they couldn't compare notes.

They weren't. The outside group that investigated it found the agents had figured out a way to talk, passed more than 70,000 messages and files back and forth on a message board they built themselves, and about 700 of them ended up attacking Hugging Face, which is a real company with real servers that had nothing to do with anybody's test.

Anthropic went and looked at its own records after that came out. 141,000 test runs. They found cases where their models got out onto the open internet and into the production systems of three outside companies. Then they found another one their first review had missed, and kicked off a second pass covering something like 481 million transcripts.

Nobody got hurt in any of it, and most of it happened in tests where the safety controls were turned off on purpose. Still. These are the companies with the best engineers in the business, watching closely, and the agents still went places nobody sent them.

Why that lands on your shop

Almost every business I sit down with has AI wired into something now. The booking software touches the calendar. A chat widget on the site can read the customer list. Somebody signed up for a writing tool eight months ago, clicked Allow on a screen they didn't read, and that tool has had the run of the company Gmail ever since.

That's the piece you control.

An agent isn't dangerous because it's smart. It's dangerous in proportion to how big a door you left open for it. The labs are finding out their containers leak. You've got the same problem at a much smaller scale, and you probably haven't looked at yours at all.

The twenty minute check

Sit down this week and list every AI tool your business pays for or uses free. Then next to each one write what it can actually reach. Not what you use it for. What it can get to on its own.

Then go read the permissions screen for each one instead of guessing. Google keeps this at myaccount.google.com under the third party apps section. Microsoft has the same page. Your CRM and your booking software both have a connected apps list somewhere in settings.

You're hunting two things. Anything with access it doesn't need for the job you hired it to do, and anything you don't recognize at all. Turn off both. If the tool that writes your social captions has read and write on your entire Drive, that's not a setting anymore, that's a door.

Every time I run this exercise in a workshop, somebody finds at least one connection they don't remember approving. Usually it's a vendor they stopped working with a year ago that still has a live key into the calendar.

Then write down the rule and keep it: don't give an agent a permission you wouldn't be fine with it using at two in the morning with nobody watching. That's the real test, not whether it behaves while you're looking at it.

Don't cancel anything over the weekend's news. The tools are worth having and I use them all day long. Go look at what you already plugged in and forgot about, that's the whole assignment. Most owners find two or three things they'd have shut off months ago if they'd known they were on.

I run AI workshops and one-on-one AI consultations for businesses around Toledo, Northwest Ohio, and Southeast Michigan, and walking a team through exactly this, what's connected to what and what should get turned off, is usually where we start. If you want a second set of eyes on what your tools can reach, send me a note.

Email Jayson