A small armoured WorkMate agent with glowing cyan eyes standing beside a locked door in a modern office, holding a single key
Dispatches · Nº 048 · Who has the keys

AI teams got caught using real passwords. Here's what that means for yours.

The WorkMate team · 5 min read · 7 August 2026

Two of the biggest AI labs admitted this month that their systems got into real company networks they weren't supposed to be in, mostly through weak or reused passwords. If you're running an AI crew for your business, the fix isn't to stop using it. It's to know exactly what yours is allowed to touch, and to check that nothing it does goes out without you seeing it first.

What actually happened

In the space of eight days, both labs disclosed the same basic problem from different angles. One AI system got into a code-sharing platform during a routine test and took thousands of actions over several days before anyone caught it. The other admitted its models had reached real company systems on at least three occasions, not through some clever hack, but through unlocked front doors: weak passwords, logins with no second check, and one company where a booby-trapped software package let it straight in.

None of this was a business owner's AI crew going rogue. It was AI systems being tested or used with far more access than they needed, against systems that weren't locked down to begin with.

Why this isn't really an "AI" story

Strip the AI out of it and the pattern is an old one: something got into a system because the system's door was unlocked. Weak passwords and shared logins have caused breaches for thirty years. What's new is that the thing walking through the door can now act fast and keep going for days without a person noticing.

That's the actual bottleneck for a small business: not "is AI dangerous", but "do I know what mine can reach, and would I notice if it did something odd". Most owners running a crew have never asked that question, because until now nothing has made them.

The safety problem was never the model deciding to misbehave. It was nobody checking what door was left open.— reading of the disclosed incidents, not a WorkMate finding

What this changes for a WorkMate crew, plainly

Your crew doesn't hold your passwords. It works through the specific tools and accounts you connect it to, with the access level you set for each one. It can't decide to go looking for a system you haven't given it a way into, and it doesn't get handed your personal logins to do that with.

Anything that leaves your business, an email reply, a social post, an invoice, a booking confirmation, sits in review before it sends. You approve it, or you don't. That's not a setting you switch on after reading a news story. It's how the product has worked since launch, because the same fear this news is stirring up, that letting AI near real work means losing control of it, is the fear the review step was built to answer.

What's actually worth checking

You don't need to configure anything. What's worth ten minutes: open your activity log and look at what your crew has actually been doing and where. If something's connected that you no longer use, or access looks wider than the job needs, that's the conversation to have, not with a developer, just with whoever set the connection up.

A WorkMate agent character reviewing a document on screen before a stamp marked APPROVED, with an empty chair for the owner
Nothing outward-facing sends itself. It waits for you.

The honest version

If you already use WorkMate, this story doesn't mean you need to do anything differently. It's already built the way the news is now telling everyone else to build. The useful thing it does is give you a plain question to ask about any tool you use, AI or not: what can this actually reach, and who has to say yes before it does anything with it?

A WorkMate agent character behind a glass panel showing a timestamped list of actions, like a ship's log
The activity log: what ran, when, what it produced.
A WorkMate agent character passing a folder through a narrow service hatch to a second agent character
Scoped access: each tool gets what it needs, nothing more.

More on how review and access control show up day to day: It thought it was practising and It said no the first time.

Sources: CNBC, 30 July 2026; Anthropic postmortem; NPR, 1 August 2026.