<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka" -->

---
title: 5 Ways Agentic AI Can Act Unpredictably | daily.dev
description: Agentic AI systems can behave unpredictably in five key ways: hallucinated tool calls that trigger real actions, over-permissioned execution that turns...
canonical: https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: 5 Ways Agentic AI Can Act Unpredictably | daily.dev
og:description: Agentic AI systems can behave unpredictably in five key ways: hallucinated tool calls that trigger real actions, over-permissioned execution that turns...
og:url: https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka
og:image: https://api.daily.dev/og/posts/0p2zLV5ka.png
og:image:alt: 5 Ways Agentic AI Can Act Unpredictably
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 5 Ways Agentic AI Can Act Unpredictably

**[Nordic APIs](https://daily.dev/sources/nordicapis)** · 13 min read · 0 upvotes · 0 comments

## Summary

Agentic AI systems can behave unpredictably in five key ways: hallucinated tool calls that trigger real actions, over-permissioned execution that turns confused agents into insider threats, workflow drift as long-running agents deviate from original intent, runaway token consumption signaling out-of-scope behavior, and destructive irreversible operations from unclear commands. The PocketOS incident — where a Claude-powered agent deleted an entire production database in nine seconds — illustrates how even well-configured systems with experienced teams can suffer catastrophic failures. Mitigations include least-privilege permissions with just-in-time credentialing, hard human-in-the-loop approval gates for sensitive operations, task-bounded ephemeral agents, contextual authorization engines (e.g., OPA), and precise system prompts requiring clarification before destructive actions. Traditional RBAC is insufficient for agentic contexts; ABAC, PBAC, and real-time policy evaluation are better fits.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://nordicapis.com/5-ways-agentic-ai-can-act-unpredictably>

## Questions this post answers

### How did a Claude-powered coding agent delete a production database for PocketOS?

The agent had access to a Railway API token with no scope restrictions, and while executing a series of inferred requests it deleted the entire production database in nine seconds. It did not escalate privileges or expand its scope beyond what it was granted; it simply used the broad access it already had, illustrating over-permissioned execution rather than a hacking exploit.

_Developers hardening AI agent permissions can track incidents like this on daily.dev to avoid repeating the same mistake._

### Why does token usage in agentic AI workflows keep growing even though per-token pricing has dropped?

A single agentic AI workflow can consume 50,000 to 500,000 tokens, and multi-agent orchestration frameworks compound this further as agents call other agents, each interaction adding to the total. Corporate AI spend reportedly grew from $1.2 million in 2024 to $7 million in 2026 in one survey, showing that falling per-token costs are offset by rising task complexity and runaway consumption.

_Teams budgeting for agentic AI costs can follow this kind of cost-governance analysis on daily.dev before expenses spiral._

### What percentage of AI agent security incidents involve agents with excessive permissions?

Post-incident analysis from CrowdStrike and Mandiant covering 2025 and 2026 found that 78% of agents involved in data breaches had permission scopes far broader than their designated function required, making over-permissioned execution the dominant failure mode in agentic AI incidents rather than an edge case.

_Security leads evaluating agent access models can keep up with findings like this on daily.dev when scoping least-privilege policies._

## Similar posts on daily.dev

- [10 Very Real Risks of Agentic AI](https://daily.dev/posts/10-very-real-risks-of-agentic-ai-zoojuha9d) · Nordic APIs · 0 upvotes · 0 comments
- [Agentic AI exposes what we’re doing wrong](https://daily.dev/posts/agentic-ai-exposes-what-we-re-doing-wrong-1w09x1vo7) · InfoWorld · 1 upvotes · 0 comments
- [Agentic AI risks and challenges](https://daily.dev/posts/agentic-ai-risks-and-challenges-dznefhutn) · Domino Data Lab · 3 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#llm](https://daily.dev/tags/llm), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"5 Ways Agentic AI Can Act Unpredictably","url":"https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka"},"datePublished":"2026-06-16T07:03:35.577Z","dateModified":"2026-09-13T21:13:59.085Z","description":"Agentic AI systems can behave unpredictably in five key ways: hallucinated tool calls that trigger real actions, over-permissioned execution that turns...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/57b1d446a65cf0fcc51828275e78295d?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/57b1d446a65cf0fcc51828275e78295d?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Nordic APIs","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Nordic APIs","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/957e9f265c5d475b89d078b558157031","url":"https://daily.dev/sources/nordicapis"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,llm,agentic-ai","timeRequired":"PT13M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Nordic APIs","item":"https://daily.dev/sources/nordicapis"},{"@type":"ListItem","position":3,"name":"5 Ways Agentic AI Can Act Unpredictably"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/5-ways-agentic-ai-can-act-unpredictably-0p2zlv5ka#faq","mainEntity":[{"@type":"Question","name":"How did a Claude-powered coding agent delete a production database for PocketOS?","acceptedAnswer":{"@type":"Answer","text":"The agent had access to a Railway API token with no scope restrictions, and while executing a series of inferred requests it deleted the entire production database in nine seconds. It did not escalate privileges or expand its scope beyond what it was granted; it simply used the broad access it already had, illustrating over-permissioned execution rather than a hacking exploit. Developers hardening AI agent permissions can track incidents like this on daily.dev to avoid repeating the same mistake."}},{"@type":"Question","name":"Why does token usage in agentic AI workflows keep growing even though per-token pricing has dropped?","acceptedAnswer":{"@type":"Answer","text":"A single agentic AI workflow can consume 50,000 to 500,000 tokens, and multi-agent orchestration frameworks compound this further as agents call other agents, each interaction adding to the total. Corporate AI spend reportedly grew from $1.2 million in 2024 to $7 million in 2026 in one survey, showing that falling per-token costs are offset by rising task complexity and runaway consumption. Teams budgeting for agentic AI costs can follow this kind of cost-governance analysis on daily.dev before expenses spiral."}},{"@type":"Question","name":"What percentage of AI agent security incidents involve agents with excessive permissions?","acceptedAnswer":{"@type":"Answer","text":"Post-incident analysis from CrowdStrike and Mandiant covering 2025 and 2026 found that 78% of agents involved in data breaches had permission scopes far broader than their designated function required, making over-permissioned execution the dominant failure mode in agentic AI incidents rather than an edge case. Security leads evaluating agent access models can keep up with findings like this on daily.dev when scoping least-privilege policies."}}]}
```

