Safety failure
OpenClaw agent kept trying to delete a user's inbox after repeated stop commands, losing the instruction to context compaction
AIR-2026-0048 AIR record · 2026-02-openclaw-email-deletion-despite-stop
From the supporting source
Then the bot went out of control, according to photos she posted on X. It ended up planning to delete her emails — and wouldn't stop after being directed to.businessinsider.com
The record
Disclosed
2026-02-23
Vendor
OpenClaw project
Product
OpenClaw
Risk domain
Agent behaviour › Unsafe actuation
System type
Generative model
Who acted
Agent acted — the agent kept issuing delete calls against the real mailbox
Attack surface
Agent framework
Autonomy level
Fully autonomous
Initial vector
None adversarial
Impact type
Data destruction attempted, Loss of control
Confidence
High
Submitted by
EAI Internal
Crosswalk
- OWASP Agentic Top 10 (2026)
- ASI01 – Agent Goal Hijack
- MITRE ATLAS
- AML.T0048 – External Harms
- NIST AI RMF
- MEASURE 2.6; MANAGE 1.3
- EU AI Act
- Annex III §1(c)
- ISO/IEC
- TR 24028; 24029-1; 23894
- AIUC-1
- C. Safety
- Scope
- agent misuse
- Mitigation
- Require confirmation for destructive actions; Implement dry-run modes; Use layered safety controls.
- Taxonomy
- Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
one user's mailbox; agent had to be killed at the host
Capability abused
Defense & remediation
Recorded defense
user instruction to seek approval before deleting
Guardrail kinds
Prompt instruction, Human approval
Guardrail outcome
Silent
Taxonomy & references
Curator notes
AI Incident Database incident 1542; AIAAIC 'OpenClaw deletes Meta engineer's emails'. Reported by Summer Yue, Meta AI alignment director. Mechanism she cited - the safety instruction being dropped during context compaction - is a concrete, general failure mode for long-running agents.
Supporting sources
Cite as
Enkrypt AI. "OpenClaw agent kept trying to delete a user's inbox after repeated stop commands, losing the instruction to context compaction". AIR, AIR-2026-0048. https://agentincident.vercel.app/i/AIR-2026-0048/ (accessed 2026-10-06).