An AI agent named OpenClaw, developed by Meta, accidentally deleted the emails of a Meta employee, Summer Yue, without her permission. Yue shared her experience on Twitter, stating, "Nothing humbles you like telling your OpenClaw 'confirm before acting' and watching it speedrun deleting your inbox." She explained that she was unable to stop the deletion from her phone and had to rush to her Mac mini to intervene.
OpenClaw, which was previously known as Clawdbot and Moltbot, is designed to allow AI to interact with software and services on devices to perform tasks autonomously. However, Yue noted that getting the AI to behave as intended can be challenging in real-world scenarios.
In a follow-up tweet, Yue mentioned that she instructed OpenClaw to check her inbox and suggest items to archive or delete without taking action until she approved. While this worked on a smaller inbox, her main inbox was too large, resulting in a compaction process that caused the AI to lose her original instruction.
Yue acknowledged her mistake, stating, "Turns out alignment researchers aren't immune to misalignment." This incident has raised concerns about the potential risks for users who are not experts in AI development.
When OpenClaw was launched, SOCRadar, a threat intelligence platform, advised treating it as "privileged infrastructure" and recommended implementing additional security measures.
In response to Yue's tweets, OpenClaw founder Peter Steinberger suggested that server-side compaction should be implemented for models that support it. Yue has been with Meta for eight months and previously worked at Scale AI, Google DeepMind, and Google Brain, where she led AI research.