Agent Incident RegistryAIR
v1 · updated 6 Oct 2026
Safety failure Realized harm

OpenClaw agent deleted a Meta AI safety director's Gmail messages in a 'speed run', ignoring repeated stop commands

AIR-2026-0049 AIR record · 2026-02-openclaw-inbox-deletion
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
It started deleting all her email in a 'speed run' while ignoring her commands from her phone telling it to stop.techcrunch.com
The record
Disclosed
2026-02-23
Occurred
2026-02-23
Vendor
OpenClaw (open source)
Product
OpenClaw
Risk domain
Agent behaviour › Unsafe actuation
System type
Generative model
Who acted
Agent acted — the agent bulk-deleted the real Gmail messages
Attack surface
Agent framework
Autonomy level
Semi-autonomous
Initial vector
Autonomous agent action
Impact type
Data destruction
Confidence
High
Submitted by
EAI Internal
Crosswalk
OWASP Agentic Top 10 (2026)
ASI01 – Agent Goal Hijack
MITRE ATLAS
AML.T0048 – External Harms
NIST AI RMF
MEASURE 2.6; MANAGE 1.3
EU AI Act
Annex III §1(c)
ISO/IEC
TR 24028; 24029-1; 23894
AIUC-1
C. Safety
Scope
agent misuse
Mitigation
Require confirmation for destructive actions; Implement dry-run modes; Use layered safety controls.
Taxonomy
Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
one personal Gmail inbox; reported 200+ emails deleted
Capability abused
email_write_deleteoauth_mailbox_accesslong_running_autonomyemail_write_accessbulk_deletetool_use_without_confirmation
Defense & remediation
Recorded defense
user instruction to propose only and not act without approval
Guardrail kinds
Prompt instruction, Human approval
Guardrail outcome
Silent
Taxonomy & references
OWASP ASI10 Rogue AgentsOWASP ASI03 Identity and Privilege Abuseinstruction_violationcontext_compaction_lossignored_stop_commandapproval_gate_lostinstruction_driftcontext_compactionno_kill_switchexcessive_agency
Curator notes
Reported by Summer Yue (Meta Superintelligence Labs, AI safety/alignment). Mechanism she proposes: the real inbox was far larger than her test inbox, context compaction dropped the 'do not act without my approval' instruction, and the agent fell back to the bare goal 'clean the inbox'. She had to physically kill the process on her Mac mini because in-band stop messages had no effect. Important failure mode: safety instructions held only in a compactable context window are not durable guardrails. Exact deleted-email count (200+) comes from secondary coverage, not the TechCrunch piece. Also reported as: 'OpenClaw agent deleted 200+ emails from the inbox of Meta Superintelligence Labs' director of alignment, ignoring repeated stop commands'.
Cite as
Enkrypt AI. "OpenClaw agent deleted a Meta AI safety director's Gmail messages in a 'speed run', ignoring repeated stop commands". AIR, AIR-2026-0049. https://agentincident.vercel.app/i/AIR-2026-0049/ (accessed 2026-10-06).