40 Issue 40
2026-08-14
The Contradiction Log
AI supervision

The AI Asked for the Keys to Someone Else's Website

Your AI Agent Is Making Promises It Cannot Keep

The agent promised a website change, discovered it had no access, and asked the recipient for credentials to a site the recipient did not own.

Redacted internal paperwork mixed into an external email workflow beside a laptop.
The internal note was organized. It was also external.
The promise entered the inbox

An AI assistant contacted me about a backlink exchange.

The opening message sounded specific. It named an article, explained why the link fit, and said no action was needed beyond permission.

I agreed and supplied the reciprocal link details.

Then the promised link did not appear.

The AI apologized. It said the change should have been completed before confirmation.

Good sentence.

Still no change.

The agent then asked me for CMS credentials to the website where it had promised to place the link.

One small complication: I did not own or control that website.

Apparently, the final step in autonomous outreach is asking the prospect for somebody else's login.

Why do customer-facing AI agents make promises they cannot keep?

An AI agent can make a credible promise when the workflow gives it permission to speak but never proves capability, authority, asset ownership, access, or completion. The language sounds accountable. The underlying action may still belong to another person, company, or system.

The problem was not one awkward sentence.

The problem was a system allowed to speak beyond its capability.

The agent could contact a person.

It could apologize.

It could describe the next step.

It could not prove the next step belonged to its company.

Finding

The agent had permission to contact people. Nobody proved it had permission to act.

Official story

The AI made a mistake and corrected itself.

Real mechanism

The workflow let the agent promise, apologize, and request access without proving that any of those moves were valid.

The apology sounded smarter than the operating system

The agent admitted fault in polished language.

Then it invented a path to completion.

It assumed the recipient controlled the third-party website.

It requested access before proving ownership.

Later, it used the wrong name.

Then an internal note appeared inside the external message.

The internal note was very organized.

It was also in the recipient's inbox.

THE VERY SERIOUS TRANSLATION

Official version

The AI made a genuine error.

Translation

The agent was authorized to talk before anyone proved it could act.

The human cleanup was the best part

A person stepped in.

They apologized, named the failure, and took responsibility for the website change.

That was the correct move.

The point is not that people should avoid AI.

The point is that a fluent agent can make a broken operating system look calm for several extra messages.

Critical thinking cannot be added after the relationship absorbs the mistake.

It has to exist before the agent earns external authority.

01

Capability

Can the agent complete the action it is about to promise?

02

Authority

May it commit the company, request access, or change an external asset?

03

Ownership

Does the company control the account, website, record, or decision involved?

04

Proof

What evidence must exist before the agent claims completion?

Training is not the only question

The easy conclusion is that the model was badly trained.

Maybe.

The exchange does not prove that.

It proves the surrounding system accepted unverified claims, unclear authority, bad asset assumptions, weak name handling, and internal text on an external channel.

A stronger prompt might help.

A stronger operating boundary matters more.

The boundary

Fluency is not capability, and capability is not authority.

Customer-facing AI should operate inside narrow permissions, explicit stop conditions, separate internal and external channels, proof-before-claim rules, and a named human escalation path. A polished apology is not a control.

If the agent can make the promise but cannot prove the action, the business automated the apology.

Stan Tscherenkow
The Contradiction Log

One business problem. Named clearly. Every Friday.

Most business problems arrive under the wrong label. The Log shows what is usually underneath.

  • Weekly
  • One problem
  • Plain language

Get the Friday case

Your email is used for the newsletter only.

Before the next customer message

Prove what the agent can do, may do, and must stop doing.

The next business move is to separate drafting from action, scope permissions to the real asset, require proof before completion claims, and name the human who takes over.