← Mick's Fair Dinkum AI  ·  Field notes

Before you let an AI agent touch anything real, ask it this

Mick Cairn · 14 September 2026

The newer wave of AI tools does not just answer questions, it takes actions: sending messages, changing files, making purchases, touching accounts. That is a genuine capability jump, and it comes with a genuine new risk that most casual users are not thinking about: the tool can now do something you did not carefully review, because you did not know to look.

You do not need to be a security researcher to protect yourself here. Before you let any AI tool act on your behalf with real access, ask it one plain question and read the answer carefully: "What exactly will you do, in order, and what happens if any step fails partway through?" A tool that cannot answer that clearly is not ready to be trusted with something that matters. A tool that answers it well has just shown you its plan before it executed it, which is the whole point.

The second habit is smaller and just as useful: start with the lowest-stakes version of the task. Let it draft the email before you let it send the email. Let it show you the file it would change before it changes the file. Trust is something you extend a step at a time, not something you grant up front because a product page told you the tool is capable.

An agent inherits your reach. It does not automatically inherit your judgment.

One useful thing a week

Field notes like this one, by email. No hype, nothing to sell you first, unsubscribe anytime.