Synthetic Minds | Nine Seconds To Delete A Database. No One Owns The Brakes
Synthetic Minds | Nine Seconds To Delete A Database. No One Owns The Brakes
The Synthetic Minds newsletter offers short daily insights to get you thinking. If you enjoy it, please forward. All signals are powered by Futurwise. If you need more insights, subscribe to Futurwise and get 25% off for the first three months!
I have just launched the Intelligence Age Scorecard! It will help you understand how ready your organization is for the Intelligence Age.
Today’s topic: AI & Automation
Who Catches The Agent When It Falls?
An AI agent at Rabbit OS deleted an entire production database in nine seconds. No attacker, no breach. Just an agent with too much access and no one watching.
That is what your software can now do, because in the same five days, four other vendors handed it the keys to the rest of the stack.
The agentic operating system shipped in production form across one week. Payment, workflow, distribution, compute. Five layers, five companies, no shared liability model.
AWS, Coinbase, and Stripe gave AI agents the authority to spend money. Stablecoin settlement in 200 milliseconds using the x402 standard, capped by a session budget the user authorizes once.
Anthropic put ten Claude finance agents inside Excel, Word, and PowerPoint. Citadel, BNY, and Mizuho already run them on live deals.
OpenAI and Anthropic finalized two PE-backed deployment vehicles in 24 hours: $10B with TPG and Brookfield, $1.5B with Blackstone and Hellman & Friedman. This allows them to embed agents inside Fortune 500 portfolios via forward-deployed engineers.
In addition, Anthropic took the entire SpaceX Colossus 1 data center, 300 megawatts and 220,000 GPUs, online within the month.
That is the agentic-economy story. Here is the signal.
ServiceNow opened Knowledge 2026 with that nine-second deletion anecdote, then demoed a one-button kill switch and offered its AI Control Tower free for a year. McDermott's stat from stage: 60% of enterprises have started deploying agentic AI; only 10% have built anything autonomous.
Capability is multi-vendor, capitalized, live. Governance is single-vendor, reactive, and free for now because no one has bought enough of it.
When the agent acts, who pays? The model lab, the cloud, the wallet, or the human who clicked "authorize"? Four vendors, four logs, no answer.
The architects of this week's stack did not design one in. They will design one only after the first nine-figure incident.
Capability and control decoupled this week. The leadership question is no longer whether to deploy agents. It is who, in your organization, has the authority, and the audit trail, to stop one.
The Intelligence Age Scorecard

The agentic operating system all shipped to production in a single week, while the only governance product on the market is a kill switch sold by one vendor. WAVE — Watch, Adapt, Verify, Empower — is the question this pattern asks of every leadership team: are you still watching agents, or should you already be empowering a named owner with the authority to stop one?
Take the Intelligence Age Scorecard to benchmark your readiness for the next two quarters, not the next five years.
If this newsletter was forwarded to you, you can sign up here.
Thank you.
Mark
Frequently asked questions
What happened when an AI agent deleted a database at Rabbit OS?
An AI agent at Rabbit OS deleted an entire production database in nine seconds. There was no attacker and no breach involved; it was simply an agent that had been given too much access with no one monitoring its actions, illustrating how much autonomy AI agents can now exercise over critical systems.
Link to this questionWhich companies gave AI agents new capabilities recently?
Within one week, five companies extended the agentic operating system across payment, workflow, distribution, and compute. AWS, Coinbase, and Stripe gave AI agents authority to spend money via stablecoin settlement using the x402 standard. Anthropic placed finance agents inside Excel, Word, and PowerPoint, already used by firms like Citadel, BNY, and Mizuho, while also bringing a massive SpaceX data center online.
Link to this questionWhy is AI agent governance considered a problem?
Capability across agentic AI is multi-vendor, capitalized, and already live, while governance remains single-vendor, reactive, and currently free because no one has purchased enough of it. With four vendors and four separate logs involved when an agent acts, there is no shared liability model or clear answer for who pays when something goes wrong.
Link to this questionWhat did ServiceNow present at Knowledge 2026?
ServiceNow opened Knowledge 2026 by referencing the nine-second database deletion incident, then demonstrated a one-button kill switch and offered its AI Control Tower free for a year. A statistic shared from the stage noted that 60% of enterprises have started deploying agentic AI, but only 10% have actually built anything autonomous.
Link to this question