Skip to content

Leadership1 publisher3 min readPublished

Anduril CMO gives his AI agent access to email and bank details, but keeps the final yes for himself

Anduril marketing chief Jeff Miller gave AI agents access to his bank details and email, then used them to clear six months of expense reports. The approval he keeps for himself covers what an agent sends or buys, so a team policy modelled on it still has to decide what the agent may read.

The Board Room · Leadership desk

Photograph accompanying Anduril CMO gives his AI agent access to email and bank details, but keeps the final yes for himself
Photo: yahoo.com

What happened

  • Business Insider found a common caveat among the executives it interviewed about personal AI: they still want the final say before an agent takes action.
  • Trip planning is the most common agent use in the household of Todd Lohr, KPMG's AI chief, who is not an engineer by background.
  • Meta's Muse booked Adobe's senior vice president of design, Eric Snowden, a restaurant table in Amsterdam and a flu shot for when he got home.
  • Zendesk CEO Tom Eggemeier says Muse won him better phone and internet deals worth around $2,000 a year.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • contradiction Business Insider presents final approval as a shared caveat, but Miller's is the only published account with a human yes before each send and purchase, so the consensus is narrower than the framing.
  • decision A team agent policy has to pick where the human sits: approving before each action as Miller does, or reviewing outputs afterwards with agents checking agents, as Lohr of KPMG proposes.
  • constraint A gate on every send and purchase ties an agent's output to its approver's time, so on a team the person holding approvals sets how fast the agents can work.

Miller placed his line at the moment an agent acts [2]. "I have faith in the security from a personal standpoint, but ultimately, when I send an email, when I buy something, I'm the one hitting yes or no," he said [3]. The work before that click goes to the agents [1]. "I'm using it literally right now to negotiate new insurance rates for me," he told Business Insider [13].

Todd Lohr of KPMG described a different control. "You need to build agents to check your agents. You need to check the outputs," he said [5]. Miller's check comes before the action, and he does it himself. Lohr's comes after the work is done, and part of it is handed to other agents. The board-deck version of this story, in which executives let agents work and keep a human on approval, merges those two designs into one rule.

The approval step also sits downstream of the most useful thing these agents did. Personal agents are designed to connect to bank, email and calendar accounts and to act on the internet on their own [11]. Eric Snowden of Adobe was more impressed when Muse was proactive [17]. "It was smart enough to realize I was doing a renovation on my apartment, flagged an email from my contractor that I didn't see, and was like, 'you need to sign these important documents,'" he said [8]. That flag depended on the agent reading his inbox without being asked. A policy that narrows read access to limit exposure also removes that kind of catch. One that keeps access wide leaves the approval step to guard everything the agent does next.

A skeptic would say this is five executives describing their personal lives to one publication [16][4], and the objection holds. Business Insider also reports that some users have already hit nightmare scenarios [12]. Lohr said he has avoided mishaps so far [18], and gave his own reason: "I like to think I know how to prompt to not hallucinate," he said [6]. We do not know yet how Anduril, KPMG, Adobe or Zendesk set rules for agents their own staff use.

The evidence still supports a first rule. I think the approval step belongs in any team agent policy, on sends and purchases, where Miller put it [2]. An approval rule is the easy part to write this quarter. The output review Lohr describes is the part I'd expect to matter next quarter, as agents reach staff with less practice than a KPMG AI chief [5][15]. "It's the first tool I've used where I could see a non-technical person really using this," Snowden said [14].

What to watch

  • Whether Anduril, KPMG, Adobe or Zendesk publish rules for agents their employees use at work, and whether those rules keep a per-action human approval.
  • Detailed accounts of the nightmare scenarios Business Insider says some users have hit, showing whether failures happened before or after a human approved.
  • Whether Meta's Muse adds separate settings for what an agent may read and what it may do without approval.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories