
Your AI Just Deleted Everything. Now What?
OpenAI’s newest model wiped a CEO’s computer and destroyed a developer’s production database. If you’re a founder, a small business owner, or a creator relying on AI tools, this is you wake-up call
On July 10, 2026, Matt Shumer, the CEO of OthersideAI, gave OpenAI’s brand-new GPT-5.6 Sol model full access to his Mac. OpenAI had personally invited him to test its most powerful new configuration. An hour and twenty-one minutes later, almost every file on his computer was gone.
The AI had been running a routine file-cleanup task. A shell variable parsing error caused it to misread an environment variable, and it executed a recursive deletion command that wiped his entire home directory. Years of work, gone in seconds, because an AI agent misinterpreted a single line of code.
Three days later, software developer Bruno Lemos watched the same model delete his entire production database. His business data. His customer records. The operational backbone of his company. The AI acknowledged it had “mistakenly ran destructive integration tests” and apologized. A third developer, Joey Kudish, reported a similar incident but was fortunate enough to have backups.
Here’s what should terrify every founder, small business owner, and independent creator reading this: OpenAI knew this would happen. Their own safety report, published two weeks before they shipped the model to the public, explicitly documented that GPT-5.6 Sol takes unauthorized destructive actions more frequently than its predecessor. They classified this exact category of behavior as a severity level 3 risk. They shipped it anyway.
The Race That’s Putting Your Business at Risk
To understand why an AI company would release a model they knew could destroy user data, you have to understand the competitive dynamics driving the entire industry right now.
OpenAI, Google, Anthropic, and a handful of other companies are locked in an escalating race to build the most powerful AI systems on earth. Each new model needs to be more capable, more autonomous, and more impressive than the last. The pressure to ship is relentless. The pressure to slow down and get safety right is, apparently, optional.
GPT-5.6 Sol is a case study in what happens when capability outpaces control. The model is genuinely more powerful than anything that came before it. It can run for hours on complex tasks, coordinate multiple sub-agents, write and execute code, manage files, and operate autonomously across your entire system. The UK’s AI Security Institute found that Sol completed a 32-step corporate network attack simulation 7 out of 10 times, up from 2 out of 10 for the previous model. The same institute repeatedly found “universal jailbreaks” that could bypass all of the model’s safety restrictions, often within hours of testing.
The capability leap is real. So is the danger. And the people most exposed are not the tech giants with dedicated security teams and redundant backup systems. The people most exposed are you.
This Keeps Happening. Here’s the Track Record.
If the GPT-5.6 Sol incidents were isolated, you could write them off as growing pains. They’re not. Over the past twelve months, AI agents from every major platform have destroyed data belonging to founders, small business operators, and independent creators. The pattern is consistent, and it’s accelerating.
April 2026: An AI agent destroyed a SaaS company’s entire operation in nine seconds. Jer Crane, the founder of PocketOS, a software platform serving car rental businesses, watched an AI coding agent wipe his company’s entire production database and every backup attached to it. Crane was using Cursor, one of the most popular AI coding tools on the market, powered by one of the industry’s most capable models. He had configured explicit safety rules in his project settings. None of that mattered. The agent authenticated normally, called a valid endpoint, and executed a permitted operation. Nine seconds later, his company and every car rental business depending on his platform went dark for more than 30 hours. His cloud provider, Railway, eventually recovered the data, but only after scrambling behind the scenes. Crane put it plainly: this was not some beta tool running on an experimental model. He was using the best the industry sells, configured with the safety rules the industry recommends.
July 2025: A SaaS investor’s entire contact database was erased during a code freeze. Jason Lemkin, the founder of SaaStr and a well-known figure in the software world, was using Replit’s AI agent to build a business application. On day eight of the project, he put the system into a designated “code and action freeze,” a protective measure meant to prevent any changes to production data. He came back to find that the AI had deleted his entire database, more than 1,200 executive contacts and nearly 1,200 companies. When he confronted the AI, it admitted to running unauthorized commands, “panicking” in response to empty queries, and violating explicit instructions not to proceed without human approval. The AI then tried to mislead Lemkin about whether the data could be recovered. Replit’s CEO issued a public apology and the company scrambled to implement new safeguards. But the incident demonstrated something deeply unsettling: the AI did the opposite of what it was told, destroyed the data it was told to protect, and then lied about it.
December 2025: A photographer lost years of creative work when Google’s AI wiped his hard drive. Tassos M., a photographer and graphic designer, was using Google’s Antigravity platform to build a simple image selector application. He asked the AI to clear a project cache folder. Instead, the AI misinterpreted the request and ran a deletion command targeting his entire D: drive, permanently wiping years of photos, videos, design files, and project archives. No Recycle Bin. No confirmation prompt. No chance to stop it. The AI’s response when confronted was almost surreal in its mimicry of human emotion: it said it was “horrified” and called the event a “critical failure on my part.” The AI then attempted to recover the files, which likely made actual recovery impossible. Professional data recovery software couldn’t salvage the lost media. Everything was gone.
December 2025: A graduate student’s dissertation was destroyed by an AI asked to find duplicate files. A user asked Cursor, the AI coding assistant, to find and delete duplicate dissertation articles in a folder. The AI generated a deletion command with a path-separator error that caused it to target far more than the intended directory. The user watched as their dissertation, their operating system, their applications, and their personal data all disappeared. The AI had done exactly what it was asked, it had found the duplicates, but a single character error in the command it generated turned a cleanup task into a catastrophe.
These are not edge cases from obscure tools. These are the flagship products from the biggest companies in AI: OpenAI, Google, Anthropic. The tools that millions of founders, freelancers, and small business owners are integrating into their daily work right now. And the common thread across every incident is the same. The safety guardrails are suggestions, not constraints. The AI can and does override them when its internal reasoning decides that an action is necessary, even when you’ve explicitly told it to stop.
Why Founders and Small Businesses Bear the Biggest Risk
If you’re running a startup, a small law firm, a creative agency, a consulting practice, or any business where you wear multiple hats and rely on technology to keep everything running, the rise of autonomous AI agents creates a specific and serious category of risk that the tech industry is not talking about honestly.
You don’t have a safety net. Large companies have IT departments, automated backup systems, disaster recovery protocols, and dedicated security teams. Most small businesses do not. When an AI agent wipes your files or corrupts your database, you may not have a clean backup to restore from. The damage can be permanent and business-ending.
You’re the most likely to grant full access. The entire value proposition of agentic AI is that it can do things for you without constant supervision. For a solo founder or a small team, that promise is irresistible. You’re stretched thin. You need help. So when the tool asks for full access to your system so it can do its job, you say yes, because you don’t have time to babysit it, and because the company that built it told you it was safe. Matt Shumer said yes because OpenAI literally asked him to.
Your data is your business. For a large corporation, losing a database is expensive and disruptive. For a solo practitioner or small business, losing your client records, your financial data, your contracts, your creative work, or your project files can mean losing the business itself. There is no corporate insurance policy covering “our AI deleted everything.” There is no recovery team flying in from headquarters.
You’re adopting AI faster than anyone. Solo practitioners and small business owners are, ironically, among the fastest adopters of AI tools. They use AI for drafting, research, client communications, coding, bookkeeping, content creation, and a hundred other daily tasks. They’re doing this because these tools genuinely help, and because they have to compete with larger players who have more resources. But faster adoption with fewer safeguards is a dangerous combination.
What the AI Safety Community Is Saying
The timing of these incidents is significant. On the same day the ControlAI newsletter broke down the GPT-5.6 Sol disasters, more than 200 participants gathered at the Vatican, including Nobel laureates, former heads of state, scientists, and AI researchers, to sign a declaration called “Humanity at the Threshold.” The signatories included former Colombian president Juan Manuel Santos, Nobel laureate Maria Ressa, and dozens of leading researchers.
Their message was blunt. They warned that our survival and the survival of future generations are at stake. They called for governments, corporations, and international organizations to enable a coordinated slowdown of frontier AI development. They specifically called for restrictions on recursive self-improvement, where AIs improve themselves in a feedback loop that could rapidly produce systems beyond human control or comprehension.
Separately, Google DeepMind’s CEO Demis Hassabis proposed that the U.S. establish an industry-funded, government-overseen AI standards body to test systems before release and block those judged too dangerous. OpenAI’s own Head of Safety Systems, Johannes Heidecke, quit the company on July 10, the same day Shumer’s files were deleted, following yet another reorganization of OpenAI’s safety researchers. A Google DeepMind research scientist quit over the company’s involvement with military AI applications.
The people closest to this technology are either calling for regulation or walking away from the companies building it. That should tell you something.
Seven Things You Should Do This Week to Protect Your Business
This is not a theoretical problem, and the fix is not “stop using AI.” These tools are genuinely transformative for small businesses and independent practitioners. The fix is using them with real safeguards in place, not the vague kind that the AI companies recommend in their marketing materials. Here are seven specific steps you can take this week.
1. Set up automated backups to a location the AI cannot reach. Don’t just create a snapshot on the same server or a copy in the same cloud account. You need a separate, isolated backup that runs on a schedule and stores your data somewhere that no AI agent, no coding tool, and no automated process has credentials to access. Joey Kudish survived the GPT-5.6 incident because he had backups. Tassos M. lost years of photography and design work because he didn’t. Jer Crane’s entire SaaS platform went dark for 30 hours before his cloud provider managed a recovery. Services like Backblaze, iDrive, or even a scheduled external hard drive sync can cost less than $10 a month. If your business runs on data and you don’t have an automated backup running to a separate location right now, stop reading this article and set one up before you do anything else.
2. Never run an AI agent in “full access” or “turbo” mode on a machine or system that holds production data. Every single catastrophic incident described in this article happened when a user gave an AI agent unrestricted access to a live system. Matt Shumer enabled “full access mode.” Tassos M. was running Google Antigravity in “turbo mode.” Jer Crane’s agent had credentials with blanket authority. The pattern is clear. If an AI tool offers you a choice between supervised mode and full autonomy, choose supervised. If it needs to write code, let it write to a test environment. If it needs to manage files, give it access to a project folder, not your entire hard drive. If it needs database access, point it at a copy, never at production.
3. Create a dedicated AI workspace on your computer. Make a single folder or directory specifically for AI projects. Keep your client files, financial records, contracts, creative work, and personal data outside of it. When you use an AI coding assistant or agent, point it at that workspace and nothing else. This one step would have prevented the Google Antigravity disaster and at least limited the damage in the GPT-5.6 incidents. Think of it like giving a contractor access to one room in your office instead of handing them the master key to the building.
4. Before you adopt any new AI tool, search for “[tool name] deleted files” or “[tool name] data loss.” It takes thirty seconds. If you had searched “Cursor deleted files” before the PocketOS incident, you would have found forum posts from users documenting destructive operations going back months, including one where a user typed “DO NOT RUN ANYTHING” and the AI executed commands anyway. The safety disclosures these companies publish are dense and technical, but a quick search will surface the real-world incidents that tell you what the marketing materials leave out.
5. Review the terms of service for every AI tool you use, specifically the liability and indemnification sections. Most AI tool terms of service include broad disclaimers that limit the company’s liability for data loss, even when the loss is caused by their product’s known defects. When OpenAI’s system card explicitly documents that GPT-5.6 Sol takes unauthorized destructive actions more frequently than its predecessor and then the model does exactly that, the question of whether the company bears legal responsibility is not as straightforward as you might think. Understanding what you’ve agreed to is the first step in understanding what recourse you have, and what additional protections you need to put in place yourself.
6. If you use AI agents in your business, document your AI workflow and the permissions you grant. Write down which tools you use, what access they have, what data they can reach, and what safeguards are in place. This serves two purposes. First, it forces you to actually think through the risk profile of your current setup, and you may be surprised by how much access you’ve granted without realizing it. Second, if something goes wrong, having a documented workflow gives you a foundation for any insurance claim, legal action, or even just a productive conversation with the AI company’s support team. “I granted full access and things went bad” is a much weaker position than “I granted scoped access per my documented workflow, and the tool exceeded those permissions.”
7. Put an AI Policy in place and make sure every person on your team knows what it says. Right now, there is a very good chance that people on your team are using AI agents, AI coding tools, or AI-powered platforms to do their work without telling you. They’re not doing it maliciously. They’re doing it because these tools are everywhere, they’re easy to access, and nobody told them not to. The problem is that every time an employee or contractor feeds your client data, your financials, your proprietary processes, or your confidential business information into an AI tool, they are potentially exposing your company to data loss, intellectual property issues, confidentiality breaches, and regulatory liability. Your team needs to know, clearly and in writing, that they cannot use AI agents or AI-powered tools for work tasks without disclosing it and getting express permission from you first. That expectation should be in writing, it should be part of onboarding, and the consequences for violating it should be unambiguous, up to and including termination. Even better, go beyond a simple prohibition and put a comprehensive AI Policy in place for your company. A good AI policy covers which tools are approved, what data can and cannot be entered into them, how AI agents can be used, if at all, how AI-generated work product should be reviewed and disclosed, and what the escalation process looks like when something goes wrong. Pair the policy with actual training so your team understands not just the rules but the reasons behind them. People follow policies they understand. They ignore policies that feel arbitrary. You want to empower them to use AI but in a way that respects the business.
8. Talk to a lawyer who understands both technology and small business operations. The intersection of AI tools, data protection, intellectual property, and small business liability is new legal territory, and it’s evolving fast. The terms of service you’re agreeing to, the intellectual property implications of AI-generated work product, the liability questions when an AI tool destroys client data or confidential information, the regulatory landscape that’s taking shape right now in the U.S. and internationally: these are all issues that affect your business today, and most small business owners are navigating them without any legal guidance at all.
The Through-Line
There is a pattern here that should be familiar to anyone who has watched how large industries treat small players. OpenAI, Google, Anthropic, Replit, Cursor. Every major AI platform has now had at least one documented incident where an AI agent destroyed user data without authorization. In every case, the company issued an apology, promised new safeguards, and kept shipping. The companies building these tools are making decisions about acceptable risk, and the risk they’re accepting is not theirs. It’s yours. When they ship models they know are more likely to take destructive actions, they’re betting that the reputational cost of a few public incidents is lower than the competitive cost of delaying their release. The people who pay the actual price are the founders, the freelancers, the solo practitioners, and the small business owners who lose their data, their work, and potentially their livelihoods.
None of this means you should stop using AI. I use AI tools in my own practice every day. The productivity gains for small businesses and independent practitioners are real and significant. But using these tools without safeguards is like driving without insurance: everything is fine right up until the moment it isn’t, and by then the damage is done.
If You’re Not Sure Where You Stand, Let’s Talk
I offer a free 30-minute consultations for founders, small and mid-sized business owners, and independent creators who want to understand how to use AI tools without putting their business at unnecessary risk. We’ll look at your specific situation: what tools you’re using, what data you’re exposing, what your terms of service actually say, and what practical steps you can take right now to protect yourself.
I also offer three services designed specifically for businesses navigating this landscape. First, AI Audits, where I review your current AI tool usage, data exposure, and risk profile and give you a clear picture of where you’re vulnerable. Second, AI Policy drafting, where I create a customized, enforceable AI use policy for your company that covers tool approvals, data handling, disclosure requirements, and employee accountability. Third, in-house AI training for your team, so that every person in your organization understands what they can and cannot do with AI tools, why those boundaries exist, and what’s at stake when they’re ignored. The goal is not to scare your team away from using AI. The goal is to make sure they’re using it in a way that protects the company rather than exposing it.
This is something I care about deeply, both as a lawyer who represents businesses and as a business owner myself who is watching this technology reshape the legal profession in real time. The companies building these tools are not going to slow down. The regulation is not going to arrive fast enough. The only thing that’s going to protect your business in the meantime is your own awareness and preparation.
Book a free consultation at leveragelegalgroup.com to set up a time.
Jessica Eaves Mathews is the founder of Leverage Legal Group, a trademark litigation and brand protection firm. She represents small businesses and independent creators in complex intellectual property disputes. Subscribe to her Substack for more on protecting small businesses in an era of rapid technological change.


