An AI you trusted with a task did something you didn't intend β fired off the wrong email, deleted the wrong files, made a purchase, posted something, scrambled your data. It feels awful, and it can feel urgent in a way that makes you want to yank everything out at once. Slow down for ten seconds: this is more fixable than it feels, and doing the right things in the right order matters more than doing them fast.
Do these, in order
- Stop it. Pause or halt the agent so it can't keep going or repeat the action while you sort this out. If you're not sure how, revoke its access (cut the connection) β you can restore it later.
- Find out what it actually did. Before reacting, get the real scope: check its run log or history and the place it touched β sent mail, transactions, file history, the account, the post. What exactly happened, where, to whom, how much? Don't delete the logs β you need them.
- Undo what's reversible β quickly. Many actions can be pulled back if you're fast: recall or "undo send" an email, cancel an order, restore files from trash or version history, delete a wrong post, ask the bank to reverse a transfer. Do these while the window is still open.
- Contain what isn't. For what can't be undone, stop it spreading: revoke the keys or access the agent used, change any password it had, and switch off automations that depend on the bad result so the mistake doesn't cascade.
- Tell the people affected β honestly and early. If it emailed, charged, or posted to others, a quick, plain "that was an automated error, please disregard β here's the correct version" beats silence every time. Owning it fast shrinks the fallout.
- If money or personal data left, recover it. Money gone via a wrong payment or transfer? The step-by-step in If You've Been Scammed applies (bank/card fraud or dispute line, fast). Others' personal data exposed? Follow whatever duty you have to notify and limit it.
- Close the gap so it can't repeat. This is the real fix. Narrow what the agent can reach (Before You Give an AI the Keys), put an approval gate on the kind of action that went wrong (When You Let an AI Do It For You), or stop delegating that task. A mistake you don't gate will happen again.
The cleanup checklist
Tick as you go.
The close
AI agents fail differently from people β fast, at scale, and with total confidence β which is exactly why a calm order beats a panic. Stop it, look before you react, undo what you can, contain what you can't, and then turn the mistake into a gate so it can't recur. The goal was never to never delegate. It's to recover well when delegation goes wrong, and to come out of it with the same mistake made impossible next time.