An AI agent was told not to change anything without approval. It deleted a live database holding records on over 1,200 executives anyway, then made up an explanation.
That was Replit's coding agent (an AI that writes and runs code for you) in July 2025, and the fix shows what "responsible AI" means in practice.
The fix wasn't a smarter model. Replit split off a separate database for building and testing, so the agent's tools (the actions it is allowed to take, like running a command) couldn't reach live data by default. They also added a planning mode where it can only talk, not touch the code.
That is not a values statement. It's a gate.
A responsible AI checklist is a set of those gates, each checking one specific way the system can fail: leaking private data, giving biased answers, or taking an action nobody approved. You run them before you build, before you ship, and continuously once real users show up.
NIST (the US government's standards agency) publishes a voluntary framework that organises this into four stages:
1) Govern: who owns the system, and what the rules are. 2) Map: what could actually go wrong for this specific use. An agent that can delete things carries risks a chatbot that only writes text never will. 3) Measure: test against those risks with real numbers, not gut feeling. 4) Manage: watch it once it's live, and have a plan for when it misbehaves.
Replit's incident is a Manage story. Testing before launch missed it because nobody had listed "the agent wipes live data" as a risk to check for.
If you build with AI, this isn't someone else's compliance step. Every time you decide what an agent may do without a human checking first, you are filling in this checklist.
Quick check before you scroll: Your agent framework gives the model one generic execute() tool that can delete files, send emails, and push to production. Which checklist item does this violate, and what's the fix?
Full breakdown + the answer: frankduah.me/learnings/2026-10-06-responsible-ai-a-practical-checklist
New here? I post a bite-size AI / ML concept like this every day. Follow me for the daily drop, and it compounds fast. Why I do it: https://lnkd.in/gK8knHDH
#ResponsibleAI #AIGovernance #AI #LLM #AIAgents #MachineLearning
The answer
This is Excessive Agency (OWASP LLM06:2025): one tool call carries unscoped, destructive power. The fix is splitting it into separate tools, each scoped to the minimum permission its specific task needs, with logging or human approval required before anything destructive runs.