AI

Giving too much power to AI, users risk losing data

Bùi Đăng Minh•Thursday, October 1, 2026•25 min read
Giving too much power to AI, users risk losing data
Doan Thuy
Doan Thuy

(Dan Tri) - AI is gradually shifting to read emails, book tickets and buy goods instead of humans. Experts warn that giving too broad permissions can cause the AI ​​to perform unintended actions on real accounts.

When AI starts working for humans

Instead of finding airline tickets, comparing prices, and filling in reservation information yourself, users can delegate these tasks to an AI assistant. The system automatically searches, chooses the appropriate option and only returns to ask when confirmation is needed.

This is the development direction of Muse, the personal AI assistant introduced by Meta in September. Unlike regular chatbots, Muse can directly use the browser, fill out forms, send emails, make purchases and handle many online tasks, even when the user has closed the application.

Giving too much power to AI, users risk losing data - 1
Meta's Muse can do many online tasks for users such as reading emails, booking tickets, making purchases and filling out forms (Photo: Future).

Meta's Muse can do many online tasks for users such as reading emails, booking tickets, making purchases and filling out forms (Photo: Future).

In an experience posted by TechRadar, journalist Lance Ulanoff named his Muse assistant Charlie and granted personal Gmail access.

When asked if he had missed any important emails, Charlie found three notable messages, including information about an unannounced technology product.

AI not only summarizes the content but also helps him compose a response letter. After being asked to edit the draft, Muse continued to complete and email as instructed.

In another situation, even though Ulanoff entered the wrong contact name, Muse still found an email containing the location and parking information for an event he was about to attend.

Giving too much power to AI, users risk losing data - 2
Unlike regular chatbots, AI agents can directly operate on authorized accounts instead of just giving instructions (Photo: Future).

Unlike regular chatbots, AI agents can directly operate on authorized accounts instead of just giving instructions (Photo: Future).

Talking to Dan Tri reporter, cybersecurity expert Ngo Minh Hieu (Hieu PC) said that the biggest change in AI agents is the ability to directly act on behalf of users, instead of just giving answers.

When AI is empowered to read emails, access websites or perform transactions, the risk no longer stops at providing false information but can lead to unintended actions on real accounts.

The danger of giving too much power to AI

To become a personal assistant, AI needs to understand the owner's schedule, preferences and private information.

An AI that knows work schedules can find suitable flights. If email is accessed, it can detect forgotten appointments. When knowing clothing sizes and shopping habits, AI can also choose products closer to your needs.

Giving too much power to AI, users risk losing data - 3
Giving email access to AI can put a lot of personal information and sensitive data at risk of being exposed if the system is exploited (Photo: Viet Huy).

Giving email access to AI can put a lot of personal information and sensitive data at risk of being exposed if the system is exploited (Photo: Viet Huy).

However, according to Mr. Hieu, the biggest risk lies in users giving too broad access rights.

If AI is allowed to read, send, or delete emails, a misinterpreted command could cause the system to take unintended action. More dangerously, attackers can install malicious instructions in emails, websites or documents that the AI ​​reads to find ways to control its behavior.

This form is called prompt injection, which means attacking by inserting malicious instructions into the information source that AI receives.

Experts call the situation where AI is given too many functions, powers or autonomy "Excessive Agency".

Giving too much power to AI, users risk losing data - 4
Cyber ​​security experts warn that AI can be exploited to perform unintended actions when given too much power (Photo: Future).

Cyber ​​security experts warn that AI can be exploited to perform unintended actions when given too much power (Photo: Future).

As for Meta, the company said Muse operates in a private computing environment in the cloud. Login information is saved in a secure area and the AI ​​does not directly see the password.

The system also has a mechanism to request confirmation before sensitive actions such as sending emails or making purchases. Users can view activity history, change or revoke access rights.

Hieu PC evaluates measures such as private virtual machines, login information storage, disposable payment cards and activity logs as necessary layers of protection. However, there is no absolute security mechanism, especially when AI can still be fooled by the content it receives.

What tasks should not be given full authority to AI?

According to Hieu PC, users can let AI perform tasks that are low-risk and easy to undo, such as finding flights, comparing prices, filling in information or preparing orders.

On the contrary, operations such as payments, money transfers, sending emails, deleting data, changing passwords or granting new access rights require a final human confirmation step.

Experts recommend applying the principle of least necessary rights. If the AI ​​only needs to search emails, users should not grant additional permissions to send or delete messages. Similarly, finding airline tickets does not require the AI ​​to have payment authority.

Giving too much power to AI, users risk losing data - 5
Users should directly confirm important operations such as payment, money transfer or changing passwords, instead of giving full authority to AI (Photo: Dan Tri).

Users should directly confirm important operations such as payment, money transfer or changing passwords, instead of giving full authority to AI (Photo: Dan Tri).

For bank accounts, work emails, sensitive data and administrative accounts, users need to be especially cautious, and regularly check and revoke unused permissions.

"The more AI has the ability to act like humans, the more granting rights to AI must be like the way we grant rights to an employee: for the right job, in the right scope, and always with limits," Hieu PC emphasized.

As AI becomes increasingly able to handle work for humans, it's important not just how much the technology does, but also how much control users can have over those actions.

Nguồn / Original source: Dân trí