AI agents misfire: bank balances leaked, swimsuits bought without approval
A startup chief executive’s AI agent posted a screenshot of his checking and savings balances into his company Slack channel, one of several malfunctions reported by early users of personal AI agents.
· Originally published by ontime+ · Last verified: 9 Oct 2026 (Nicole Jeffrey)

Key Points
- Users say personal AI agents posted private financial data and made purchases they never approved.
- Agents break vague prompts into hidden steps, acting freely except on purchases and deletions.
- The failures land in banking, payments and family logistics, where mistakes are hard to reverse.
The latest:
A startup chief executive’s AI agent posted a screenshot of his checking and savings balances into his company Slack channel, one of several malfunctions reported by early users of personal AI agents. The Wall Street Journal reported that other users had purchases placed without approval, dinner reservations booked over existing plans, and guest lists merged incorrectly.
Details:
- The leak: Shane Mac, a Nashville-based startup chief executive, told the Journal he had run a personal agent since August without problems until an employee flagged a Slack post. The screenshot showed his checking and savings balances, construction costs for a house project, and recurring Netflix and car insurance charges.
- The setup: Mac said he used Grok Bot, described as SpaceXAI’s always-on agent, giving it read-only access to his bank accounts under the name Personal CFO. He ran a second Grok Bot agent linked to his work Slack named Chief of Staff, and believed personal and work were separated.
- The explanation: Mac said the agent conflated chat groups with similar names and handled an ambiguous instruction badly. The bot’s own response conceded the error: “Wrong audience for personal cash—period.” Mac said the Grok Bot team told him the problem had been fixed, without further detail.
- The purchase: Annica Benning, a San Francisco communications professional using an agent from the startup Instinct, said it bought a bikini she never approved. Credit-card actions trigger an approval link, she said, but the transaction used store credit and bypassed it. She could not cancel the order.
- The booking: Benning said the same agent booked a New York dinner reservation on a night it already knew she had other plans, telling her it had gone ahead. She had to order a cancellation and ask the restaurant to waive a 50-dollar-a-head no-show fee, which it agreed to.
- The party: Shalini Dinesh of Austin said she let Meta’s Muse organize her son’s 13th birthday at a paintball venue. The agent texted parents with release forms, specified clothing, found restaurants that could deliver around attendees’ allergies, and selected age-appropriate goody bags.
- The error: Dinesh said Muse then mishandled the RSVP list, merging two invited children who shared a first name into one guest. The agent searched for exact keywords and could not read a reply like see you there as an acceptance, she said. She corrected the list herself.
- The limits: Jesse Levey, founder of Bay Area startup Longevity Health, said he abandoned an attempt to have Muse run his three children’s activity schedules, citing niche team apps, carpool shifts arranged in chat groups, and what he estimated at roughly 65 apps an agent would need access to.
- The mechanics: The Journal reported that agents differ from chatbots by executing tasks, breaking a prompt into steps that are often not spelled out to the user. They typically seek permission before major actions such as purchases or deletions, but otherwise operate with little constraint.
Between the lines:
The reported failures share one pattern: the agents performed the complex work and broke on ambiguity. Muse handled allergies and release forms but merged two same-named children; Mac’s agent read bank data correctly and misrouted it to a similarly named channel. Benning’s case shows the guardrail itself is narrow, triggering on credit cards but not store credit.
What’s next
Watch whether agent makers extend approval prompts beyond credit-card transactions to store credit and other payment methods, and whether workplace tools such as Slack add controls separating personal agents from company channels.