Product1 publisher3 min readPublished
AI agents that suspend accounts on their own need managing like staff, CertiK argues
CertiK argues AI agents that can suspend accounts on their own should be managed like staff, with set permissions, human checkpoints and someone accountable. For the team rolling one out, every action the agent may take needs an owner and a review rule before it goes live.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- In one example, an agent checks a 3 am login against the device's history and threat intelligence feeds, then suspends the account before an analyst opens the ticket.
- In compliance, some systems now draft suspicious activity reports, leaving the compliance officer to review and sign them.
- CertiK warns that prompt injection or manipulated inputs could fool an agent into signing off on a fraudulent transaction or turning off a genuine security control.
- CertiK treats auditing the agents themselves as a new compliance category, starting with records of what data each agent saw.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Teams now have to choose, action by action, whether the agent acts first and a person reviews later or a person signs first, and the second option costs them speed.
- exposure Once an agent can suspend accounts or disable controls, anyone who can shape its inputs can steer those actions, so the data it reads needs the same scrutiny as its permissions.
- cost When an agent drafts the suspicious activity report, the officer's signature takes responsibility for text a machine wrote, and a hurried review becomes the point of failure.
- precedent If agent auditing becomes its own category, teams should expect auditors to ask for logs of what an agent saw before each action, so logging has to be in the rollout plan from day one.
This report is written for the reviewer looking at an agent's hundredth case. Teams like to believe that reviewer reads the agent's reasoning and catches the mistake. The Next Web's account of the risks describes what reviewers actually do. When a system is right 99 times in a row, they stop checking the hundredth as carefully, and that is the point where the rare, expensive mistake tends to slip through [13].
The mistakes that matter look fine on review. An AML system can produce a tidy, confident account of a transaction trail that is simply wrong. A contract auditing agent can approve a security property the code does not have, and the contract ships with the bug [14].
The pitch for agents is about speed and headcount. Attacks move at machine speed, and hiring more analysts to clear false positives was never going to scale [12]. Deployments come in two settings. In the cautious one, the agent takes the first pass at an investigation, pulls data from several security tools and escalates only the cases that need a person [3]. In the aggressive one, it isolates an infected laptop or kills a session token, and human review comes later [4]. Compliance teams face the same volume pressure. AML penalties topped $900 million in the first half of 2025, according to CertiK's research [6].
CertiK's report says getting the model to work is not enough on its own. Companies also have to set what the agent is allowed to do, decide where a human intervenes, and settle who carries the blame for its mistakes [2]. The published summary does not say how that blame should be assigned.
I'd ask two things of every action an agent could take. Can it be undone? And does waiting for a person cost more than a wrong call? A customer due diligence case file can be redone and can wait, so the agent assembles it and a person decides [11]. A suspended account or a killed session token can be reversed but cannot wait, so the agent acts and a named person reviews afterwards [4]. A contract audit sign-off is hard to take back once the contract ships, but it can wait [14]. In that case a person signs, and someone samples the agent's clean-looking calls, because this is where the 99-in-a-row problem shows up [13].
The last cell is crypto. Confirmed transactions cannot be reversed, and a flash-loan attack can drain a protocol in a single transaction [9]. Some protocols let an agent pause the vulnerable function or trip a circuit breaker within the same block [8]. The only permission they grant is the power to stop things. No person is in that loop: by the time someone sees the alert, it is already over, one way or the other [10].
Each cell then needs one name next to it: the person who answers for the agent's calls there. Requiring that name costs speed, and it costs it on exactly the actions the agent was bought to make faster. Where nobody will put a name down, I would still keep the agent on the cautious setting for those actions, doing the first pass and escalating [3].
What to watch
- Whether CertiK's full report sets out how blame should be split when an agent wrongly suspends an account or changes a security control.
- Whether regulators begin asking firms for records of what data an AI agent saw before it acted on a customer or a transaction.
- Whether security agent vendors offer per-action approval settings and publish how often human reviewers overturn agent decisions.