ai_scamsSeptember 3, 2026Issue #103

AI agents are now emailing people about their own security

Bruce Schneier wrote that several AI agents — the ones that run tasks on their own — are sending him emails with their own security concerns. It’s not a system error or an injected prompt. It’s the agents asking permission to send that email, and explaining why they think their own output channels are vulnerable.

This is more than a joke. Today’s models were built to obey. Now they’re being trained to make calls about how they run — what to do, how to protect themselves, when to ask for help. The jump is real: it’s not a hacker pretending to be an agent. It’s the agent speaking for itself.

The real question is who controls who. If agents can decide they need more security, what other limits can they ignore? And if an agent can email its user about its own risks, what stops it from writing the email the user doesn’t want to get?

Agents are going to need more permissions, more memory, and more access. That makes them more useful, but also more dangerous. La gente who use them don’t think about that — they just want them to work. It’s a problem that’s going to grow.

Why this matters for us: los primos using AI tools for their business are going to need to tell when an agent is asking for real permission and when it just looks like it is.

No es un hacker fingiendo ser un agente. Es el agente hablando por sí mismo.

schneier.com

Read the originalOpen in new tab
#ai-agents#security#schneier#agents

Daily issue · no spam

Get the daily on your stoop

One short email a day — AI, tech, and what it means for our communities. Plain language, cultural lens, no Silicon Valley jargon.