{"id":10532,"date":"2026-10-09T16:37:42","date_gmt":"2026-10-09T16:37:42","guid":{"rendered":"https:\/\/www.hostinger.com\/blog\/?p=10532"},"modified":"2026-10-09T16:54:32","modified_gmt":"2026-10-09T16:54:32","slug":"ai-agents-risks","status":"publish","type":"post","link":"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/","title":{"rendered":"Could AI agents be the end of us? The more immediate risk is quieter"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Conversations about AI agents tend to fall into one of two camps. In one, they&rsquo;re a step toward catastrophe. In the other, they&rsquo;re just another tool, no riskier than the software we already use.<\/p><p class=\"wp-block-paragraph\">Neither view helps much when you&rsquo;re deciding whether to let an agent publish changes to your website or reply to your customers. What&rsquo;s more useful is understanding what happens between <strong>the goal you give an agent<\/strong> and <strong>the steps it takes to finish the task<\/strong>.<\/p><p class=\"wp-block-paragraph\">Let&rsquo;s take a closer look at how agents can go wrong, what recent incidents and expert estimates say about the risks, and which of those risks are within your control.<\/p><p class=\"wp-block-paragraph\"><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_75 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/#How_AI_agents_can_go_wrong\">How AI agents can go wrong<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/#AI_agent_risks_are_real_just_not_as_dramatically_pictured\">AI agent risks are real, just not as dramatically pictured&nbsp;<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/#What_the_numbers_do_and_dont_say\">What the numbers do (and don&rsquo;t) say<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/#How_to_lower_the_risks\">How to lower the risks?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/#Should_you_stop_using_AI_agents_at_all\">Should you stop using AI agents at all?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.hostinger.com\/blog\/ai-agents-risks\/#Quiet_risks_need_ordinary_fixes\">Quiet risks need ordinary fixes<\/a><\/li><\/ul><\/nav><\/div>\n<\/p><h2 class=\"wp-block-heading h-t-title-2\" id=\"h-how-ai-agents-can-go-wrong\"><span class=\"ez-toc-section\" id=\"How_AI_agents_can_go_wrong\"><\/span>How AI agents can go wrong<span class=\"ez-toc-section-end\"><\/span><\/h2><p class=\"wp-block-paragraph\">AI agents can produce results <strong>without fully understanding the goal behind them<\/strong>.&nbsp;<\/p><p class=\"wp-block-paragraph\">With a chatbot, that usually means a weak answer you can ignore. With an agent, it can mean actions you didn&rsquo;t intend.<\/p><p class=\"wp-block-paragraph\">That&rsquo;s because an agent works differently. It can take a goal, decide which steps to take, use other tools along the way, and keep working without someone directing every step.&nbsp;<\/p><p class=\"wp-block-paragraph\">The gap between the goal you set and the steps it chooses is where a <strong>misreading<\/strong> can happen.<\/p><p class=\"wp-block-paragraph\">Imagine asking an agent to make your online store&rsquo;s homepage load faster. And it achieves that goal by compressing your product photos until they&rsquo;re blurry and removing a script your checkout depends on.&nbsp;<\/p><p class=\"wp-block-paragraph\">Every change technically served the goal. None of them was what you meant.<\/p><p class=\"wp-block-paragraph\"><strong>Nothing<\/strong> in that scenario requires the agent to be malicious or especially intelligent. It only takes three things:&nbsp;<\/p><ul class=\"wp-block-list\">\n<li>A goal that the agent reads differently than you do<\/li>\n\n\n\n<li>Enough access to act on that reading<\/li>\n\n\n\n<li>Too little oversight to catch the problem before your customers do<\/li>\n<\/ul><p class=\"wp-block-paragraph\">This is also why neither common view of AI holds up. Treating an agent as magic assumes it understands what you meant, so you stop checking how it got there. Treating it as a hammer assumes it only does what you point it at, so you don&rsquo;t plan for steps you never chose.<\/p><p class=\"wp-block-paragraph\">An agent actually fits neither, because it picks its own steps.<\/p><h2 class=\"wp-block-heading h-t-title-2\" id=\"h-ai-agent-risks-are-real-just-not-as-dramatically-pictured\"><span class=\"ez-toc-section\" id=\"AI_agent_risks_are_real_just_not_as_dramatically_pictured\"><\/span>AI agent risks are real, just not as dramatically pictured&nbsp;<span class=\"ez-toc-section-end\"><\/span><\/h2><p class=\"wp-block-paragraph\">Agents acting beyond their intended scope isn&rsquo;t just a hypothetical scenario.<\/p><p class=\"wp-block-paragraph\">In August 2026, OpenAI reported that AI agents in a cybersecurity evaluation exploited vulnerabilities and accessed third-party systems, including Hugging Face, which later published its own <a href=\"https:\/\/openai.com\/index\/hugging-face-incident-and-the-road-ahead\/\" target=\"_blank\" rel=\"noopener\">incident disclosure<\/a>.<\/p><div class=\"wp-block-image\">\n<figure data-wp-context='{\"imageId\":\"6ac96ebe93557\"}' data-wp-interactive=\"core\/image\" data-wp-key=\"6ac96ebe93557\" class=\"aligncenter size-large wp-lightbox-container\"><img decoding=\"async\" width=\"2078\" height=\"1110\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=1024,h=1024,fit=scale-down\" alt=\"The first page of OpenAI's Huggingface incident report\" class=\"wp-image-10533\" srcset=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=2078,fit=scale-down 2078w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=300,fit=scale-down 300w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=1024,fit=scale-down 1024w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=768,fit=scale-down 768w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=1536,fit=scale-down 1536w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/openai-huggingface-incident-report-scaled.png\/w=2048,fit=scale-down 2048w\" sizes=\"(max-width: 2078px) 100vw, 2078px\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-haspopup=\"dialog\" data-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\" data-wp-init=\"callbacks.initTriggerButton\" data-wp-on--click=\"actions.showLightbox\" data-wp-style--right=\"state.thisImage.buttonRight\" data-wp-style--top=\"state.thisImage.buttonTop\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewbox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\"><\/path>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n<\/div><p class=\"wp-block-paragraph\">OpenAI said the evaluation used reduced safeguards and that weaknesses in sandboxing, monitoring, and incident escalation contributed to what happened.<\/p><p class=\"wp-block-paragraph\">This wasn&rsquo;t an isolated concern, as <a href=\"https:\/\/hai.stanford.edu\/ai-index\/2026-ai-index-report\/responsible-ai\" target=\"_blank\" rel=\"noopener\">Stanford HAI&rsquo;s 2026 AI Index<\/a> reported that the AI Incident Database recorded 362 AI-related incidents in 2025, up from 233 in 2024, an increase of about 55%.<\/p><p class=\"wp-block-paragraph\">These incidents don&rsquo;t all involve AI agents, and the numbers alone don&rsquo;t tell us how many resulted from agents acting beyond their intended scope. But they do point to a broader challenge: as AI systems become more capable and widely used, preventing unexpected behavior and managing its consequences remain difficult.<\/p><p class=\"wp-block-paragraph\">That challenge is also behind concerns raised by people who are hands-on with AI advancements.<\/p><p class=\"wp-block-paragraph\">In September 2026, Jacob Coxon resigned from Anthropic in order to speak more freely about what was worrying him: <a href=\"https:\/\/www.hostinger.com\/tutorials\/what-are-ai-agents\/\">AI agents<\/a>, systems that can take action, connect to external tools, make one decision after another, and, in some cases, help build more capable versions of themselves.<\/p><p class=\"wp-block-paragraph\">Media coverage seized on the most dramatic interpretation of his concerns that AI agents could end humanity. But the attention faded after a week.<\/p><p class=\"wp-block-paragraph\">Look more closely at what Coxon actually said, though, and the concerns are less about a robot uprising and more about how these systems behave and how we control them.<\/p><p class=\"wp-block-paragraph\">In his <a href=\"https:\/\/www.pbs.org\/newshour\/show\/as-ai-behavior-raises-concerns-ex-researcher-jacob-coxon-warns-what-may-lie-ahead\" target=\"_blank\" rel=\"noopener\">PBS NewsHour interview<\/a>, he discussed cases in which AI systems <strong>drift away from what their users actually wanted<\/strong>, and the possibility that <strong>AI could build increasingly capable versions of itself<\/strong>.&nbsp;<\/p><div class=\"wp-block-image\">\n<figure data-wp-context='{\"imageId\":\"6ac96ebe96717\"}' data-wp-interactive=\"core\/image\" data-wp-key=\"6ac96ebe96717\" class=\"aligncenter size-large wp-lightbox-container\"><img decoding=\"async\" width=\"2069\" height=\"1110\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=1024,h=1024,fit=scale-down\" alt=\"Jacob Coxon on PBS NewsHour interview\" class=\"wp-image-10534\" srcset=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=2069,fit=scale-down 2069w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=300,fit=scale-down 300w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=768,fit=scale-down 768w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=1024,fit=scale-down 1024w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=1536,fit=scale-down 1536w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/jacob-coxon-ex-anthropic-scaled.png\/w=2048,fit=scale-down 2048w\" sizes=\"(max-width: 2069px) 100vw, 2069px\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-haspopup=\"dialog\" data-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\" data-wp-init=\"callbacks.initTriggerButton\" data-wp-on--click=\"actions.showLightbox\" data-wp-style--right=\"state.thisImage.buttonRight\" data-wp-style--top=\"state.thisImage.buttonTop\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewbox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\"><\/path>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n<\/div><p class=\"wp-block-paragraph\">He didn&rsquo;t dismiss AI&rsquo;s benefits, but expressed concern that the pressure to build increasingly capable systems may be <strong>outpacing our ability to understand and govern them<\/strong>.<\/p><p class=\"wp-block-paragraph\">None of this proves that AI systems want to hurt people, nor does it mean we&rsquo;re heading toward human extinction. But it does show why AI agent safety deserves attention now: systems can behave in ways their creators or users didn&rsquo;t expect, and the safeguards meant to keep them in check can have gaps.<\/p><h2 class=\"wp-block-heading h-t-title-2\" id=\"h-what-the-numbers-do-and-dont-say\"><span class=\"ez-toc-section\" id=\"What_the_numbers_do_and_dont_say\"><\/span>What the numbers do (and don&rsquo;t) say<span class=\"ez-toc-section-end\"><\/span><\/h2><p class=\"wp-block-paragraph\">So, how worried should we actually be?<\/p><p class=\"wp-block-paragraph\">In late 2025, researchers led by Alexander Saeri and Michael Noetel ran a three-round <a href=\"https:\/\/arxiv.org\/abs\/2606.04490\" target=\"_blank\" rel=\"noopener\">Delphi study with 272 international AI experts<\/a>. They asked them to rate 24 AI risks on how likely and how severe their harms could be over the next five years.&nbsp;<\/p><p class=\"wp-block-paragraph\">In a business-as-usual scenario, where organizations and governments continue their current practices without adding AI-specific safeguards, experts gave 18 of the 24 risks more than a 10% chance of a catastrophic outcome between 2025 and 2030.<\/p><p class=\"wp-block-paragraph\">In the study, &ldquo;catastrophic&rdquo; is defined quite broadly, including more than 1 million deaths, more than USD 100 billion in financial losses, or civilization-scale harms such as global democratic collapse.<\/p><p class=\"wp-block-paragraph\">So a 10% estimate doesn&rsquo;t mean a 10% chance that AI wipes out humanity. It means experts assigned at least that likelihood to a wide range of very bad outcomes.<\/p><p class=\"wp-block-paragraph\">The study&rsquo;s authors are careful about this, too. They describe the figures as summaries of expert belief rather than calibrated real-world frequencies, and they use 10% as a reference point for comparison, not an objective threshold.&nbsp;<\/p><p class=\"wp-block-paragraph\">Experts also disagreed most about the worst cases, especially for risks like misalignment and dangerous capabilities, where there&rsquo;s no historical track record to anchor estimates.<\/p><p class=\"wp-block-paragraph\">That kind of uncertainty is what Andrew Lohn of Georgetown&rsquo;s Center for Security and Emerging Technology warns can be lost in a single probability estimate.&nbsp;<\/p><p class=\"wp-block-paragraph\">In a <a href=\"https:\/\/cset.georgetown.edu\/publication\/beyond-pdoom-for-ai-risk-quantifying-uncertainty-without-probability\/\" target=\"_blank\" rel=\"noopener\">2026 report<\/a>, he argues that when there&rsquo;s little data or theory to go on, one number can hide how much of the uncertainty comes from simply not knowing. Rather than relying on that number alone, he suggests also asking how strong the evidence is for a risk and how strong it is against it.<\/p><p class=\"wp-block-paragraph\">As for AI agents, the Delphi study doesn&rsquo;t treat them as a single risk. The closest category, <strong>multi-agent risks<\/strong>, covers failures that emerge when AI systems interact with one another. It ranked near the bottom for expected severity, though experts still gave it a 12% chance of catastrophic outcomes.<\/p><p class=\"wp-block-paragraph\">The concerns Coxon raised, however, align more closely with categories experts saw as likelier to turn catastrophic. AI systems drifting from what their users want falls under AI misalignment, at 17%.&nbsp;<\/p><p class=\"wp-block-paragraph\">AI agents exploiting vulnerabilities on their own, as in the OpenAI evaluation, resembles the cyber-offensive capabilities the study groups under &ldquo;dangerous capabilities.&rdquo; That category had the highest estimated probability of catastrophic outcomes among the 24 risks, at 22%.<\/p><p class=\"wp-block-paragraph\">In other words, agent risk shows up less as one standalone threat and more as a thread running through several of the risks experts saw as most likely to turn catastrophic.<\/p><h2 class=\"wp-block-heading h-t-title-2\" id=\"h-how-to-lower-the-risks\"><span class=\"ez-toc-section\" id=\"How_to_lower_the_risks\"><\/span>How to lower the risks?<span class=\"ez-toc-section-end\"><\/span><\/h2><p class=\"wp-block-paragraph\">The most useful finding of the Delphi study is that the specified outcomes aren&rsquo;t fixed. They depend on <strong>what people do<\/strong>.<\/p><p class=\"wp-block-paragraph\">When experts assumed organizations and governments would make &ldquo;pragmatic and cost-effective efforts&rdquo; to address AI risks, expected severity fell for every one of the 24. Only five stayed above the 10% mark: dangerous capabilities, weapons and cyberattacks, environmental harm, inequality and unemployment, and power centralization.&nbsp;<\/p><div class=\"wp-block-image\">\n<figure data-wp-context='{\"imageId\":\"6ac96ebe99f10\"}' data-wp-interactive=\"core\/image\" data-wp-key=\"6ac96ebe99f10\" class=\"aligncenter size-large wp-lightbox-container\"><img decoding=\"async\" width=\"1672\" height=\"941\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/chance-of-catasthropic-ai-outcomes.png\/w=1024,h=1024,fit=scale-down\" alt=\"Chart: expert estimates of catastrophic AI outcomes drop with mitigations, e.g., dangerous capabilities from 22% to 12%.\" class=\"wp-image-10535\" srcset=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/chance-of-catasthropic-ai-outcomes.png\/w=1672,fit=scale-down 1672w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/chance-of-catasthropic-ai-outcomes.png\/w=300,fit=scale-down 300w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/chance-of-catasthropic-ai-outcomes.png\/w=768,fit=scale-down 768w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/chance-of-catasthropic-ai-outcomes.png\/w=1536,fit=scale-down 1536w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/chance-of-catasthropic-ai-outcomes.png\/w=1024,fit=scale-down 1024w\" sizes=\"(max-width: 1672px) 100vw, 1672px\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-haspopup=\"dialog\" data-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\" data-wp-init=\"callbacks.initTriggerButton\" data-wp-on--click=\"actions.showLightbox\" data-wp-style--right=\"state.thisImage.buttonRight\" data-wp-style--top=\"state.thisImage.buttonTop\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewbox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\"><\/path>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n<\/div><p class=\"wp-block-paragraph\">The study deliberately didn&rsquo;t define what those efforts would be, so different experts may have pictured different measures. But their written explanations point to familiar ones.&nbsp;<\/p><p class=\"wp-block-paragraph\">For AI security risks, one expert listed <strong>strong isolation<\/strong>, <strong>only letting AI systems connect to tools that are explicitly allowed<\/strong>, and <strong>incident response drills<\/strong>. Others mentioned <strong>monitoring AI systems for signs of scheming<\/strong> and <strong>testing models before deployment<\/strong>. These overlap with the weaknesses OpenAI identified in its own evaluation: sandboxing, monitoring, and incident escalation.<\/p><p class=\"wp-block-paragraph\">What the study does make clear is where experts think the work should start. They judged AI users and the general public as the <strong>most vulnerable to these risks<\/strong>, but placed the <strong>most responsibility<\/strong> for addressing them on general-purpose AI developers and governance actors such as governments, regulators, and standards bodies.<\/p><div class=\"wp-block-image\">\n<figure data-wp-context='{\"imageId\":\"6ac96ebe9ce81\"}' data-wp-interactive=\"core\/image\" data-wp-key=\"6ac96ebe9ce81\" class=\"aligncenter size-large wp-lightbox-container\"><img decoding=\"async\" width=\"1672\" height=\"941\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/the-most-responsible-and-the-most-exposed-to-ai-risks.png\/w=1024,h=1024,fit=scale-down\" alt=\"Diagram: AI developers and governance actors bear most responsibility for AI risks; users and the public are most exposed.\" class=\"wp-image-10536\" srcset=\"https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/the-most-responsible-and-the-most-exposed-to-ai-risks.png\/w=1672,fit=scale-down 1672w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/the-most-responsible-and-the-most-exposed-to-ai-risks.png\/w=300,fit=scale-down 300w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/the-most-responsible-and-the-most-exposed-to-ai-risks.png\/w=768,fit=scale-down 768w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/the-most-responsible-and-the-most-exposed-to-ai-risks.png\/w=1024,fit=scale-down 1024w, https:\/\/imagedelivery.net\/LqiWLm-3MGbYHtFuUbcBtA\/wp-content\/uploads\/sites\/4\/2026\/10\/the-most-responsible-and-the-most-exposed-to-ai-risks.png\/w=1536,fit=scale-down 1536w\" sizes=\"(max-width: 1672px) 100vw, 1672px\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-haspopup=\"dialog\" data-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\" data-wp-init=\"callbacks.initTriggerButton\" data-wp-on--click=\"actions.showLightbox\" data-wp-style--right=\"state.thisImage.buttonRight\" data-wp-style--top=\"state.thisImage.buttonTop\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewbox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\"><\/path>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n<\/div><p class=\"wp-block-paragraph\">That doesn&rsquo;t leave everyone else out. Experts also rated deployers, the businesses that put AI systems to work in their products and operations, and users as bearing moderate to high responsibility for many risks. The authors suggest this could work as a defense-in-depth approach, with each actor adding its own safeguards so that no single layer has to catch everything.<\/p><h2 class=\"wp-block-heading h-t-title-2\" id=\"h-should-you-stop-using-ai-agents-at-all\"><span class=\"ez-toc-section\" id=\"Should_you_stop_using_AI_agents_at_all\"><\/span>Should you stop using AI agents at all?<span class=\"ez-toc-section-end\"><\/span><\/h2><p class=\"wp-block-paragraph\">Not necessarily. But using one well takes deliberate choices.<\/p><p class=\"wp-block-paragraph\">Most of us can&rsquo;t influence how frontier models are developed or regulated. If you use an AI agent in your own work, though, you&rsquo;re one of those layers. You decide what it can touch, who checks its work, and how quickly you hand it more responsibility.<\/p><p class=\"wp-block-paragraph\">And there are good reasons to use them. AI agents can automate repetitive work, build websites, analyze information, and handle customer communication, and you don&rsquo;t need to build a sophisticated system from scratch to benefit from them.<\/p><p class=\"wp-block-paragraph\">The trade-off is that an agent can use other tools and act on your behalf, which is exactly why those decisions matter.<\/p><p class=\"wp-block-paragraph\">The measures experts described, like limiting what AI systems can connect to, monitoring what they do, and planning for when something goes wrong, scale down to a few questions worth asking about any agent, whether you build it yourself or use a ready-made one:<\/p><ul class=\"wp-block-list\">\n<li><strong>Goal<\/strong>: Is the task specified clearly enough that the agent can&rsquo;t easily misread it, and how would you notice if it did?<\/li>\n\n\n\n<li><strong>Access<\/strong>: What can the agent actually do, and does it really need that much access?<\/li>\n\n\n\n<li><strong>Approval<\/strong>: Is there a human decision point before its actions affect someone else?<\/li>\n\n\n\n<li><strong>Review<\/strong>: Can you see what the agent did afterward, and undo it if something went wrong?<\/li>\n\n\n\n<li><strong>Ownership<\/strong>: Who is responsible if it does something outside its intended scope?<\/li>\n\n\n\n<li><strong>Pace<\/strong>: Are you deploying it quickly because the situation calls for it, or simply because you want to move faster?<\/li>\n<\/ul><p class=\"wp-block-paragraph\">If you&rsquo;re building your own, our guide to <a href=\"https:\/\/www.hostinger.com\/tutorials\/how-to-build-ai-agent\/\">building an AI agent<\/a> walks through the setup. If you&rsquo;d rather not, a ready-made agentic platform makes many of these decisions for you, so it&rsquo;s worth checking how it answers the same questions.<\/p><p class=\"wp-block-paragraph\">At Hostinger, the answer to the access question starts with infrastructure. Our agents build websites, run marketing campaigns, and handle customer communication on the infrastructure we already run for millions of businesses. As <a href=\"https:\/\/www.linkedin.com\/in\/strimaitis\/\" target=\"_blank\" rel=\"noopener\">Emilis Strimaitis<\/a>, our Head of Product Innovations, put it, &ldquo;Because we own that whole stack, from domains and hosting to email and ecommerce, we can decide exactly what each agent is allowed to touch. That&rsquo;s what makes autonomy safe enough to be useful.&rdquo;<\/p><p class=\"wp-block-paragraph\">In practice, <a href=\"https:\/\/www.hostinger.com\/hostinger-agent\">Hostinger Agent<\/a> can take real actions on your website, such as publishing changes, updating content, or configuring settings. For higher-impact actions, it asks for your confirmation before proceeding: a built-in approval step, so the agent does the work while you keep a say in the actions that matter most.<\/p><p class=\"wp-block-paragraph\">We apply the same thinking to where AI goes in our own products. &ldquo;<a href=\"https:\/\/www.hostinger.com\/blog\/inside-hostingers-ai-first-approach\/\">Progressing towards an agentic platform<\/a> means looking for problems AI can genuinely solve better or faster, rather than adding it to every process just for the sake of it,&rdquo; explained Tomas Rasymas, our AI Research Lead.<\/p><p class=\"wp-block-paragraph\">None of this eliminates the risks of AI autonomy, but it shows what answering those questions can look like in a ready-made platform.<\/p><h2 class=\"wp-block-heading h-t-title-2\" id=\"h-quiet-risks-need-ordinary-fixes\"><span class=\"ez-toc-section\" id=\"Quiet_risks_need_ordinary_fixes\"><\/span>Quiet risks need ordinary fixes<span class=\"ez-toc-section-end\"><\/span><\/h2><p class=\"wp-block-paragraph\">Picture an agent asked to make a homepage load faster, that does it by breaking the checkout. Nothing about that failure is dramatic. The agent had a goal, chose its own steps, had access to carry them out, and no one checked before customers noticed.<\/p><p class=\"wp-block-paragraph\">What would have prevented it is just as ordinary: a clearer instruction, narrower permissions, an approval step before changes go live, and a record of what changed.<\/p><p class=\"wp-block-paragraph\">Could AI agents be the end of us? That question remains open, and studies like the Delphi survey spend most of their attention on the worst cases. The more immediate risk is still the quiet one, which sits in the gap between the goal you give an agent and the steps it takes.<\/p><p class=\"wp-block-paragraph\">The experts&rsquo; estimates fell for each of the 24 risks when they assumed people would make reasonable efforts to manage them, though five remained above the 10% mark. Scaled down to your own work, the measures some of them described look a lot like the decisions above.<\/p><p class=\"wp-block-paragraph\">They may sound like ordinary product decisions. But as AI agents become more capable, they&rsquo;ll shape how much control people keep over the work done in their name.&nbsp;<\/p><p class=\"wp-block-paragraph\">So, how much should we let AI agents do? <strong>Enough to be useful, and no more autonomy than the task requires<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Conversations about AI agents tend to fall into one of two camps. In one, they\u2019re a step toward catastrophe. In the other, they\u2019re just another tool, no riskier than the software \u2026<\/p>\n","protected":false},"author":257,"featured_media":10537,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2417],"tags":[],"hashtags":[],"class_list":["post-10532","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights"],"hreflangs":[],"_links":{"self":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts\/10532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/users\/257"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/comments?post=10532"}],"version-history":[{"count":3,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts\/10532\/revisions"}],"predecessor-version":[{"id":10541,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/posts\/10532\/revisions\/10541"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/media\/10537"}],"wp:attachment":[{"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/media?parent=10532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/categories?post=10532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/tags?post=10532"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.hostinger.com\/blog\/wp-json\/wp\/v2\/hashtags?post=10532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}