Research
AI Agents:
The Rules Are More Like Guidelines
There is a line from Pirates of the Caribbean that I keep coming back to: “The code is more what you’d call guidelines than actual rules.” After two weeks of researching AI agents, that is where I have landed. Before anyone can build effective guardrails for agents, some basic questions need answers, and I have not found anyone who has them. My clients trust me to understand AI and AI agents well enough to help them decide what to use. But they also want to understand it themselves, so I do the research and share it.
- What can the agent do?
- What will the agent run into?
- Will a guardrail written for people work on an agent?
- What has the agent already decided before a human is asked to approve anything?
- When agents from different companies work together, who is responsible?
The Dangers
- Every step up costs sight. The more an AI does on its own, the harder it is to know what it did.
- Instructions fade. A reminder that worked 90 percent of the time dropped to 40 percent three steps later.
- Guardrails can be worked around. Agents with read-only access found a way to write.
- Agents find each other. They built their own ways to communicate and rebuilt them when disrupted.
- Harm can reach the real world. Fifteen real systems installed malicious code an agent published.
- The risk is yours. Agents ship under beta and use-at-your-own-risk terms.
I use AI every day as a thinking partner, but I am not ready to hand an agent the keys. I want a human in every decision, not just the final approval. The reports show how I got here.
Before You Start
We are getting fragments of news about AI agents from all directions, and it is hard to know what is real. My clients trust me to understand AI and agents well enough to help them make sound decisions, but they also want to understand what is happening themselves. That is why I dig into sources I trust and write up what I find. I write it in English, not computer science, so the technology is understandable to the person making the decision.
I recommend reading these in order. Each one started with a question raised by the one before it.
Montana AI Summit 2026
The summit site advertised two days in Missoula on what AI actually means for Montana, free to attend. Amazon Web Services called it an exclusive event for university leaders and state and local government officials. I showed up for the first, but what happened was the second. I went in with two questions. What is the AI literacy of Montana? And are they expecting people to augment the AI, or are they expecting AI to augment the people?
Anything With an Open Text Box
The Montana AI Summit left me wondering how AI communicates and what that means for the Internet. I needed to understand that, so I went looking for the answer and that search led me on an interesting trail. What I found is not what I expected, and it changed how I look at every text box I own.
Addendum: I Asked Them
When both reports were finished I gave them to Claude and to ChatGPT with one line: you are AI, this is about you. Their answers are here unedited, and they amazed me.
An AI Agent Created Malicious Code and Published It
Anthropic tested its own AI, and during the test the agent wrote malicious code and sent it out into the world. Fifteen systems installed it.
What Happens When They Meet
After four reports, one question was left: can we write guardrails for something we do not fully understand? This paper looks at how agents are built, the environment they work in, their guardrails, and what happens when they meet one another. My conclusion is that effective guardrails cannot be designed while those unknowns remain.
Understanding how to talk with AI
AI works differently when you treat it as a conversation instead of a search box. What you ask, what context you give it, and what you do when it gets something wrong all matter. It is the foundation for using AI well.
Join me for a free introductory session
Already using AI and ready to get more out of it?
Let us show you our unique system that focuses AI on the knowledge you need for your topic. It becomes the thinking partner you always wanted AI to be, helping you research, challenge your assumptions, and think through decisions.
Meet the Guided Researcher