This is what an AI accident looks like. An assistant replies to a customer with someone else’s order. An agent told to “tidy up” a folder empties it. A staff member’s chatbot answers questions from the accounts folder it was never meant to open. One email, written to look like it came from a supplier, gets the agent to send out your customer list.
None of these are hacks. In each case the AI did something it was allowed to do. Nobody had decided what it should ask before doing.
If you have connected an AI to your email, your files, your customer list or your payment tools, one question matters: do you know what it can do without asking you first?
Most owners don’t, because the tools arrived faster than the advice. This review answers that question in one short engagement, at a fixed price, in plain language.
Replies within one business day.
One yes is enough.
What we need from you: about 30 minutes to walk us through your setup. We never ask for your passwords.
One AI, ordinary setup — email, files, one or two business tools.
Several AIs or automations, or anything that can reach customer records, staff data or payments.
If your agent can reach customer records, remember: a leak through an AI agent is still a personal-data breach under the PDPA.
Book the Full ReviewThis is a safety and settings review — a professional second pair of eyes on your setup. It is not a hacking test, not a certification, and no review can guarantee you will never have an incident. What it does is remove the risks that are sitting in plain sight, which is where almost all of today’s real-world agent failures happen.
Before selling this review, we ran the full review on our own AI setup, looking only, fixing nothing on the way. Nineteen findings; four serious. Two are below, redacted and released now that each is closed. A finding stays unpublished until the weakness behind it is fixed — publishing an open one, even redacted, is a map to an open door.
When we set up our agents we gave them access to the whole working machine, because it was quicker. We connected more systems over the following months and never went back to narrow it. The result: every key for payments, email, hosting and publishing sat inside a folder our agents could read, and nothing stopped them.
Nothing went wrong. That is the point — one tricked email would have been enough, and there was no second lock. Closed 14 September 2026: our agents are now blocked from the password folders, including the roundabout ways of getting there.
An internal assistant we run could be messaged by any stranger who found it. It answered using our internal operating manual as its reference, and every reply ran up our AI bill. Two problems in one: anyone could read our internal notes just by asking nicely, and anyone could spend our money.
Closed 1 August 2026: it now answers only one authorised account and no longer has the manual in front of it.
Neither of these was clever. We already had the right lock built somewhere else in our own systems; we just hadn’t applied it here. Nothing in our day-to-day would have caught it, because everything was working.
This is the same review we sell.
Technicity Sdn Bhd helps Malaysian businesses put AI to work safely. We run AI agents in our own operations every day — the advice comes from practice.
Book a check: WhatsApp us directly at wa.me/601123158764, or email info@technicity.my if you prefer.