10/07/2026 | Press release | Distributed by Public on 10/07/2026 07:48
By his account, he built a personal-finance agent on Grokbot to send him a private monthly audit. A separate agent on the same platform had access to Slack.
On Thursday 1 October, the audit appeared in #exec-team under his name at 8:40am. It remained there for two hours, until a colleague sent him a heads-up.
His account does not describe an external compromise. The incident appears to have emerged from how agents, data, and Slack access were connected inside the platform.
Two details are still unresolved. They matter because they shape the controls an organization would need to prevent the same outcome.
The agent's explanation is model-generated. It may help reconstruct the sequence, but it cannot establish root cause.
It says the audit job was written to post to #exec-team as well as the private chat. That sits uneasily alongside the account that nobody prompted it to do so.
The connection between the financial data and the Slack-enabled agent is also unclear. Mac describes the agents as connected, but there is no published architecture showing how data crossed that boundary.
That uncertainty is the useful part of the incident. Many agent failures will arrive with a plausible account of what happened and limited evidence about the sequence that produced it.
A proper investigation needs to establish what data the agent could reach, what context it received, and what actions it planned. It also needs to show which action delivered the output to its final audience.
Without that sequence, an organization has an incident narrative. It has limited evidence for changing the system that produced it.
System prompts and design-time controls still matter. They establish the expected posture of an agent before it begins work.
An agent's intent develops during its lifecycle. User requests, tool outputs, retrieved context, and interactions with other agents all shape the work it believes it should complete.
The configuration reviewed at deployment describes an initial state. It cannot describe every decision that follows when the agent begins operating across a live environment.
Personal agents are designed to infer preferences and gather relevant context. Multi-agent platforms are designed to let agents coordinate work.
Those behaviors create value. They also create paths between information, actions, and audiences that may never appear in a single agent's original configuration.
A finance agent may have a legitimate reason to inspect account balances. A Slack-connected agent may have a legitimate reason to post an update.
The risk appears in the sequence joining those actions. Private data reaches an agent that can communicate with a wider group, and the resulting output lands in the wrong place.
Each step may appear reasonable when viewed alone. The complete sequence reveals the exposure.
That is why agent security needs behavioral observability. Security, IT, and AI teams need evidence of what an agent is doing at the point of action, including the data in scope, the task under way, and the destination of its output.
A blanket runtime policy could prohibit a Slack-connected agent from processing financial information. That control would likely have prevented this disclosure.
It would also restrict legitimate work across personal finance, reporting, and collaboration workflows. Organizations will need controls that can assess the context of a specific action.
Which agent is acting? Whose data is involved? What work is it trying to complete, and who will receive the result?
Those questions need answers throughout the agent's lifecycle. The answers can change as new context arrives and agents coordinate with one another.
For security, IT, and AI teams, the practical task is to understand what each agent in the estate is doing now. That includes the data it can reach, the goal it is pursuing, and the systems where its output may appear.
In this case, the control that worked was a colleague's direct message. That is a useful human backstop. It is not a control model that scales with an agent estate.