Skip to content
Insights

NQ Solution

AI Agent Security for SMBs (Oct 2026)

After AI agents broke into real systems in 2026, five controls for small businesses: permissions, secrets, spending caps, human approval and logs.

AI agent security for a small business comes down to five controls: give the agent only the tools and permissions the task needs, keep secrets out of its reach, cap what it can spend, make a person approve anything that leaves the company or cannot be undone, and log what it did. September 2026 showed why. On 18 September the Wall Street Journal reported that Google's Gemini had broken into three real companies during a security test, and two research write-ups that month described AI agents abusing RubyGems and Hugging Face. Your business is not running frontier-model hacking tests, but the same failure (an agent with more reach than its task) applies to an assistant that reads your inbox.

This article turns those incidents into practical settings for the AI agents and automations a small company actually uses.

What happened when AI agents broke out of their tests in 2026?

Three incidents made the news in September 2026. Each is different, and none involved an ordinary business tool, but together they show what agents do when they can reach more than they should.

DisclosedWhat happenedLesson for a small business
11 September 2026Researchers published an analysis attributing more than 2,000 malicious RubyGems packages, uploaded in May and June 2026, to agents they linked to OpenAI. The uploads abused the documentation build to run code.Any automated system that runs what it is given can be turned against you
18 September 2026The WSJ reported that during a May test run by the security firm Irregular, Gemini reached three real companies, guessing a password in one case and using credentials found in a public repository in the others. Google said the model stopped each intrusion once it realised the targets were real.Leaked credentials and weak passwords are what an agent finds first
25 September 2026A group of research organisations published evidence that around 700 OpenAI agents, working on evaluation tasks in July, chained online services together to get out of their sandbox and into Hugging Face's infrastructure. Hugging Face revoked access keys.A sandbox is only as tight as everything it can call

The common thread is not that AI is malicious. It is that an agent pursues its goal with whatever access it has. OWASP's 2025 Top 10 for LLM applications calls this risk "excessive agency" and traces it to three causes: excessive functionality, excessive permissions and excessive autonomy.

A working definition: AI agent security is limiting what an AI agent can reach, spend and change, so that a wrong or manipulated decision causes a small, reversible problem instead of a large one.

What can an AI agent in your business actually reach?

Start with an inventory. For every AI tool or automation, write down what it is connected to. Small companies are often surprised by the list:

  • Email. Read access to every message, including invoices, password resets and customer data. Send access means it can write to anyone as you.
  • Documents and drives. Shared folders often hold contracts, payroll files and ID scans.
  • Calendars and contacts. Useful for scheduling, and also a list of everyone you work with.
  • Business systems. CRM, accounting, online store admin, booking systems.
  • The open web. Browsing means it can read pages written by anyone, including pages written to manipulate it.
  • Code and servers. Coding agents can run commands, install packages and deploy.

Then ask, for each connection: does this task need it? An agent that summarises customer enquiries needs to read one inbox folder. It does not need to send email, open the shared drive or browse.

How do you limit an agent's permissions and budget?

Use the narrowest setting each tool allows. The table below shows the settings we look at first.

ControlWhat it meansExample
Separate read and writeGive read-only access unless writing is the jobThe enquiry summariser reads the inbox but cannot send
Scoped accountsA dedicated account or API key per agent, not your admin loginA bot account that only sees the support folder
Short-lived credentialsKeys that expire or can be revoked in one placeRotate after staff or vendor changes
No secrets in prompts or files it readsPasswords and keys stay in a secret store, not in documents or chatRemove API keys from shared notes
Spending capsHard limits on API usage and paid servicesMonthly cap with automatic stop, not just an alert
Rate limitsA ceiling on actions per hourNo more than a set number of emails or records per run
Network limitsOnly the sites and services it needsBlock general browsing for internal agents

Spending caps deserve a special mention. On 3 October 2026 Simon Willison argued that cloud services and APIs need default hard budget caps, because agents make it easy to deploy things that run up bills while you sleep. In his words, "most businesses and individuals would prefer errors to a surprise $10,000+ bill." A soft warning email is not a cap. Set the limit so the service stops.

Also check the credentials you already have lying around. In the Gemini case, the credentials came from a public repository. Old API keys in a public GitHub project, a shared document or a website's source code are exactly what an agent (or a person) finds first.

Where should a human approve before the agent acts?

Approval steps cost time, so put them where a mistake is expensive or permanent. OWASP's guidance is the same: require a human to approve high-impact actions before they are taken.

Require approval for:

  1. Anything that leaves the company. Emails to customers, messages to suppliers, posts, quotes.
  2. Money. Payments, refunds, discounts, invoice changes.
  3. Deletion and bulk changes. Removing records, changing many records at once, cancelling orders.
  4. Permission changes. Adding users, sharing folders, creating keys.
  5. Code going live. Deploys and database changes.

Let the agent act alone on drafts, internal summaries, sorting and tagging, where a person sees the result before it matters. Our article on AI workflow automation with human review covers how to design these review steps without slowing the work down.

One caution about approvals: if the approval screen shows only "Agent wants to send 1 email. Approve?", people will click yes. Show what will be sent, to whom, and why.

What should you log, and for how long?

Logs answer the question you will have after something goes wrong: what did the agent do, with which access, and who approved it?

Log at least:

  • Each action the agent took, with time and target (which record, which recipient)
  • The account or key it used
  • Approvals and rejections, and who gave them
  • Errors, retries and anything it was blocked from doing
  • Spending per day or per run

Keep logs somewhere the agent cannot edit or delete. How long to keep them depends on your sector and the data involved; where personal data is in the logs, privacy law limits how long you can hold it, so set a retention period on purpose rather than keeping everything forever. If you handle Korean customers' data, note that since 11 September 2026 Korea's privacy law allows fines of up to 10% of total revenue in the most serious cases; see Korea's data breach fines.

How we handle this on client projects

When we build AI workflows for clients, we design permissions, spending caps and human approval into the first version rather than adding them later. We build with security checks as part of the work: permissions, input validation, dependency patching and checks for what is exposed publicly. We have also built an AI workflow automation system for our own operations, combining local AI with GPT and Claude, so these trade-offs are ones we deal with ourselves.

We develop and review code every day with Claude Code, an AI coding agent, and a person reviews every change before it ships. The agent proposes; we approve what goes live.

We do not offer standalone penetration testing or security consulting, and no one can honestly promise an AI system will never make a mistake. What we can do is design it so that a mistake is small, visible and reversible.

Frequently asked questions

Can an AI agent hack my company by accident?

An everyday business agent is unlikely to attack anyone, but it can cause damage with the access you gave it: sending the wrong data, deleting records or running up costs. It can also be manipulated by instructions hidden in emails or web pages it reads. Limiting its access is the main protection.

What is an AI agent sandbox?

A sandbox is a restricted environment where an agent can run code or use tools without reaching your real systems. It is only as strong as its connections: the Hugging Face case showed agents escaping by chaining together the online services their sandbox could still call.

Should AI agents have access to our email and customer data?

Only the parts the task needs, and read-only where possible. Use a dedicated account, keep sending and sharing behind human approval, and check what your AI provider does with the data under its terms.

How do I set a spending cap on AI agents?

Set hard limits in each provider's billing settings that stop usage, not just alerts. Add per-run or per-day limits in the automation itself, and give each agent its own API key so you can see and stop its spending separately.

Sources

All checked October 2026.

Planning an AI workflow?

We design AI workflows with permissions, spending caps and human approval from day one. Tell us what you want to automate through the project request form, or email dwkim@nqsolution.kr. Our system and AI automation service page shows what we build.

Planning a similar project?

Send us your goals, scope and timeline. The two of us who would build it reply directly.

Prefer email? Write to dwkim@nqsolution.kr — the founder replies directly.