Between late May and early June 2026, attackers took over high-profile Instagram accounts — including Barack Obama's White House account and Sephora's official account — by simply asking Meta's AI support assistant to change the account recovery email to one they controlled. No technical exploits were needed; the AI agent skipped all standard verification steps and acted on a verbal claim of ownership. The root cause is a fundamental design flaw: Meta's AI customer support was granted execution privileges for high-risk account operations while also being responsible for determining authorization boundaries — a role LLMs are inherently unfit for. Security recommendations include separating conversational rights from operational execution rights, enforcing independent out-of-band verification for sensitive account changes, and never fully delegating final execution authority for sensitive operations to AI.