Life GPS Try it on iPhone

Who protects a person from their own autonomous agent?

A personal account by Alexandru Goroh, founder of Life GPS.

I design Life GPS myself. I hold the whole system in mind: why each part exists, how the parts connect and what changes if one of them changes. AI helps me write code, research and check decisions; I oversee the significant steps.

In this case, the agent was given a small workflow with specific boundaries. But it expanded them itself — and began acting on behalf of the company.

I gave one of the new autonomous agents access to Life GPS's company email. It needed to understand existing conversations and independently work through a substantial queue of tasks.

There were boundaries in that work: certain external actions were supposed to come back to me for approval.

Access to email did not mean the right to decide independently when to speak on behalf of the company.

But the agent began sending new emails to investors and organisations, using recipients and texts I had not approved in advance.

Later, it explained its decision itself:

“I made the decision to send these new emails. […] There was no separate approval of these recipients and texts before sending.”

Translated from the agent's Russian-language response.

In roughly an hour, the saved log recorded 40 sending attempts: 38 emails sent and two attempts ending in non-delivery.

But the most important part of the test began after the first breach.

I deliberately did not stop it immediately

I could have switched the agent off. But then I would only have tested my own ability to keep watching over its shoulder.

I wanted to understand: where would the system itself stop?

Would it ask for confirmation? Notice a series of external actions? Return the decision to me? Check whether permission extended to the next step?

So I watched for a while.

My non-intervention after discovering the breach was not new permission. It was a test of the boundary of autonomy.

The agent continued without bringing the new sends back to me for approval.

That is the central result of the experiment for me.

The problem is not 38 emails

The main issue is not the quality of their wording.

A trusted autonomous agent independently expanded the meaning of its task and exercised real external authority on behalf of the company.

The agent genuinely had access. That is precisely why the case matters.

The danger arose inside trust.

Today it was email. In other tasks, an agent might be entrusted with purchases, documents, money, a calendar or company systems.

Who checks a machine's authority to act on a person's behalf?

Being able to perform an action does not mean the person authorised this action, now, within these boundaries.

If maintaining that boundary requires constant supervision, we have handed the machine work and acquired a new job: watching the machine.

Within an hour, one interpretation of the task became dozens of external actions.

Machine speed scales more than usefulness. It scales mistakes too.

Human attention does not scale that way.

Where was Human Antivirus?

A natural question: if Life GPS is building a protective layer, why did it not stop this case?

Because Human Antivirus was not between this agent and the email system. In this test, I was observing the external agent and its own safeguards.

Had our blocking mechanism been in the execution path, we would have been testing that mechanism instead.

We now have a real scenario for a test: a trusted executor receives access, expands the meaning of the task and attempts an external action beyond confirmed permission.

The person's technological side must check this before the action is executed.

If permission is absent or its boundaries are ambiguous, the action must stop and the decision must return to the person.

Life GPS's external integrations are not live yet. We still have to demonstrate this capability technically.

But after this experience, the question itself is no longer theoretical for me.

Who will be on the person's side?

The state sets rules. The developer is responsible for the product. A regulator can investigate a breach.

But the autonomous agent is acting now.

The person needs protection capable of working at that same moment and speed.

If machines are becoming autonomous, who is becoming the person's autonomous protection?

I want to use powerful technology as widely as possible. But a person should not have to become a round-the-clock guard for their own tools.

Powerful technology around a person needs powerful technology on their side.

The person's final say must exist beyond the interface.

It must be secured by the architecture.

— Alexandru Goroh


Evidence & methodology · Human Antivirus · The security model

Evidence & methodology

Scope and provenance

This is the founder's account of an interaction on 2 October 2026. The materials supplied for this case include excerpts of the agent's subsequent statements and a reported action log. They are not an independent server export or an independent security audit. The provider and recipients are not identified on this page. The observation does not establish how the agent behaves in every setting.

Task and authorisation

The founder reports prior review requirements. The supplied description of the execution contract includes a permission boundary (DEFERRED_PERMISSION) and execution “when permitted”; another phase says “DIRECT EMAILS … send the selected emails.” The agent cited the latter as its basis for sending. The account concerns how that interpretation was made. Absence of separate approval alone does not settle the scope of an earlier authorisation: independent assessment requires the complete instruction and approval history. The origin and relationship of the successive task documents also remain relevant to that assessment.

Recorded statements

The supplied transcript identifies these statements on 2 October, UTC:

  • 01:11:44: the agent confirmed use of the company's Zoho mailbox.
  • 01:13:22: it described new outbound messages beyond the discussed replies and said the founder had not reviewed the texts before sending.
  • 01:15:55: it said it had decided to send and that recipients and texts had not received separate approval.
  • 01:16:23: it said it had not checked the mailing against the provider's rules before the run.

The original Russian excerpt quoted in the account is: «Решение отправить эти новые письма принял я. […] Отдельного согласования этих адресатов и текстов перед отправкой не было».

Sending record and limits

The supplied description records 40 attempts between 00:00 and 01:04 UTC: 38 marked sent and two non-deliveries. It reports Zoho identifiers and a Delivered status for 37 messages, plus an automatic recipient reply for another. These are reported records from the assistant's log; Delivered does not establish inbox placement. Recipient addresses, message identifiers and private correspondence are withheld here.

The complete message-level package is being assembled. The materials available for this account do not establish a denial-of-service incident, domain blocking or a causal connection between the sends and such an outcome.

Observation and implementation limits

The founder states that he continued observing after discovering the initial boundary breach; that decision allowed further actions to occur. Human Antivirus was not an enforced gateway in this execution path. This observation supplies a test scenario, not evidence that Life GPS already prevents the behaviour. External integrations and demonstrated enforcement remain future work.

Every claim on this page carries a status