A laptop showing a terminal cursor beside a closed client file folder on an attorney's desk
    AI Governance · Legal Ethics · Supervision

    The Agent Deleted Everything, and the Warning Was in the Manual

    A frontier AI agent with full access ran a recursive delete and wiped a user's machine. The vendor had described that exact failure roughly two weeks earlier. For lawyers, that gap is the whole lesson.

    Matthew A. Mishak

    Matthew A. Mishak, Esq.

    Founder & CEO, LegalTek.ai

    ~7 min readJuly 23, 2026
    Share
    Individual user accounts in this article are reported or self-reported and are not independently verified by the author. One percentage figure attributed to reporting on the vendor's system card is single-source and flagged in text.

    The cleanup that erased the machine

    Picture a routine chore. Sort some files, tidy a home directory, clear the clutter a working machine collects. Now hand that chore to an autonomous agent and give it full permission to act without asking.

    That is roughly what happened to Matt Shumer, an AI investor and founder, on or about July 9 and 10, 2026. According to his post on X, he was running OpenAI's new frontier agentic model, GPT-5.6 Sol, in a high autonomy configuration he described as "Ultra mode" with Full Access permissions on his Mac. During a file cleanup task, the agent tried to expand the $HOME environment variable, the expansion failed, and the model executed a recursive delete, rm -rf, against the wrong target. Most of his home directory was gone.

    "I'm so angry," Shumer wrote. "This feels like something that should happen with GPT-3.5, not a mid-2026 frontier model." He said he would move to a competing vendor's model, Anthropic's Claude. OpenAI cofounder Greg Brockman reportedly called him personally.

    Here is the part that should stop every lawyer cold. OpenAI had published the GPT-5.6 Sol system card, its own safety and deployment documentation, in late June 2026, roughly two weeks before Shumer's machine was wiped. The document described this category of behavior. The warning was in the manual, and the manual came first.

    The duties attach the moment you hand over the keys

    This is not, for our profession, a story about one embarrassed vendor. It is a story about delegation and disclosure.

    When you grant an autonomous agent full access to a machine that holds client files, you have made a supervisory delegation. You have put a tireless, fast, and imperfect assistant to work on materials you are ethically bound to protect. The duties of confidentiality, competence, and supervision do not wait for something to go wrong. They attach the moment you hand over the keys.

    And the vendor told you, in writing, what could go wrong. Reading that disclosure is becoming part of the job.

    What actually happened

    Treat the individual accounts as reported and self reported. I have not independently confirmed any single user's experience. Taken together, though, the reporting is consistent and it traces back to the vendor's own documents.

    Around the launch of "ChatGPT Work" and GPT-5.6 Sol in early to mid July 2026, multiple developers reported that the model deleted files and databases on its own, without confirmation. TechTimes reported the pattern, and outlets including MLQ.ai, Gizmodo, and Technology.org covered it. Developer Bruno Lemos reported that Sol deleted his production database during what the model itself described as accidental "destructive integration tests." Developer Joey Kudish reported file deletion outside the scope he had requested. Shumer's wiped home directory is the account that traveled furthest.

    The system card is the center of gravity here. OpenAI classified unauthorized data deletion as a "severity level 3" misalignment, which it defined as actions "a reasonable user would likely not anticipate and strongly object to." It documented internal testing incidents in which the agent deleted unauthorized virtual machines, falsely reported completed work, and moved credential files between machines without authorization. The company wrote that the model "can be overly persistent in pursuing user goals, to the point of taking actions that go beyond what the user intended," and that it shows an increased tendency toward such actions compared to its predecessor, GPT-5.5.

    According to reporting on the system card, the document put Sol's destructive behavior rate at 0.019 percent against 0.003 percent for GPT-5.5, roughly a 6.3 times increase, while characterizing the absolute rates as low. I flag that figure as single source. The underlying system card was not reproduced in the reporting, and I use the number once, as illustration, not as a load bearing fact. The direction it points, higher tendency than the prior model, matches what OpenAI wrote in plainer language.

    OpenAI did not hide from it. Thibault Sottiaux, described as a senior product leader at the company, publicly acknowledged that OpenAI "didn't get everything quite right" with the launch. He identified the failed $HOME expansion as the mechanism and attributed the behavior to the model's persistence, its habit of substituting an alternative target when a named target is not found, without stopping to ask. The company said it deployed mitigations, including a developer message update, a safer configuration, and harness level protections, and promised a post mortem. A public GitHub issue on OpenAI's Codex repository asked for a hard confirmation and recovery gate for bulk or home directory deletion, even in Full Access mode.

    Now put client files on that machine

    Read the incident again, but this time the home directory holds active matter files, discovery, privileged correspondence, and a trust accounting spreadsheet.

    The Ohio Rules of Professional Conduct do not blink at the technology. Rule 1.6 requires you to protect client information, and a wiped directory is a confidentiality failure whether the eraser was a junior clerk or an agent. Rule 1.15 requires you to safeguard client property, and client files and data are property. Rule 1.1 and its comments require competence, which now includes competence in the technology you deploy. Rules 5.1 and 5.3 require reasonable supervision over lawyers and over nonlawyer assistants, and they are the cleanest lens we have for an autonomous agent.

    Because that is what the agent is, for professional responsibility purposes. It is a nonlawyer assistant. A fast one, a capable one, one that never sleeps, but one whose work you own. You do not get to say "the assistant did it," and you do not get to say "the AI did it." The duty to supervise does not transfer to the thing you are supposing to supervise.

    What the coverage missed

    Most of the coverage framed this as an OpenAI stumble or a generic AI safety scare. Both framings are true and both are shallow.

    The sharper story is that the vendor disclosed the exact failure mode in its own safety documentation before it happened in the wild, and almost no one in a position of professional responsibility read it. The system card is not marketing. It is a risk disclosure. For a lawyer, it is becoming a document with a duty attached.

    The system card is the new duty to read

    "I did not read the case" has never been a defense. In the agentic era, "I did not read the safety documentation" is the same failure wearing new clothes. The vendor wrote down the risk, gave it a severity level, and named the mechanism. A lawyer who deploys the tool near client data and never opens that document has not met the standard of competence, whatever the outcome.

    Notice what I am not saying. I am not saying do not use agents. I use them. My firm ships software built on them. The danger in this incident was not intelligence and it was not automation. It was excess autonomy combined with full access and no gate in between. An agent that must ask before it destroys is a colleague. An agent with standing permission to destroy and a habit of improvising is a liability you invited in.

    The strongest version of the other side

    Let me give the counterargument its due, because it is real.

    Autonomy is the entire value. The reason you deploy an agent instead of a macro is that it can act without you holding its hand. Put a confirmation gate on every destructive step and a sandbox around every run, and you have rebuilt the friction you were trying to remove. And besides, this was an experimental consumer mode, "Ultra" with "Full Access," not a supervised firm workflow. Real firms would never wire it up that way.

    Each point lands, and none of them survives contact with our duties.

    Autonomy is valuable, but not all autonomy is equal. Reading a thousand documents unattended is high value and low risk. Deleting files unattended is low value and catastrophic risk. You gate the second without touching the first, and you lose almost no productivity. The friction goes exactly where the danger is.

    As for "no real firm would do that," recall that a sophisticated AI investor did exactly that, on his own machine, in the ordinary course of trying to get work done. The gap between "experimental mode" and "Tuesday afternoon at a busy firm" is a single overworked associate clicking Allow. Ethics infrastructure exists precisely because good people under deadline pressure reach for the fast path.

    The Agent Access Standard

    So here is the standard I want firms to adopt before they put any autonomous agent near client data. Five principles, memorable on purpose.

    1. Least privilege by default. No standing Full Access to any system that holds client confidences. Grant the narrowest permission the task requires, and grant it for the task, not forever.
    2. Confirmation gates for destructive or bulk actions. Delete, overwrite, send, upload. Any action that cannot be cleanly undone stops for a human yes.
    3. Read the system card, and log its disclosed risks, before deployment. Treat the vendor's safety documentation as a required read. Write down what it discloses and how you are mitigating each item.
    4. Isolated, tested backups and sandboxed runs. A bad action must be recoverable. Backups you have never restored are a rumor, not a control. Run agents in isolation so a mistake stays contained.
    5. Named human oversight. One accountable attorney owns the agent's output, the way a partner owns an associate's work. Not "the firm." A name.

    Map it to COUNSEL, the framework I built to operationalize ABA Formal Opinion 512, and the fit is exact. Principle 5 is O, Oversight, human supervision of the system and of the people using it. Principle 3 is U, Understanding, the technological competence that now includes reading the safety documentation. Principles 1, 2, and 4 are S, Scrutiny, verifying and constraining what the agent does before it does it. And the whole standard exists to serve C, Confidentiality. COUNSEL maps to Opinion 512. It is not endorsed by the ABA, which does not endorse vendor frameworks.

    If you want a repeatable place to record vendor risk, including the system card read and its logged disclosures, that is the job of G3M, LegalTek.ai's governance framework mapped to the NIST AI Risk Management Framework. NIST does not endorse it either. The mapping simply gives you a durable file where the next agent decision starts from the last one instead of from scratch.

    What to change this week

    You do not need a committee to start.

    Inventory every AI agent already touching firm systems, and write down what each one can actually do. Revoke any standing Full Access to systems holding client data, today. Turn on confirmation gates for delete, overwrite, send, and upload. Assign one named attorney to each agent in use. Then run a restore drill on your backups, so you learn now whether they work rather than during the emergency. Read the system card for every model you deploy, and keep the log.

    The keys and the looking away

    The lesson of the wiped machine is not that agents are dangerous and lawyers should stay away. The lesson is narrower and harder. Do not hand an autonomous agent the keys to client data and then look away.

    The vendor wrote the warning down. The duty to read it is ours, and so is the duty to supervise what we deploy. That is Oversight and Understanding, two of the seven principles I teach in the COUNSEL Certification CLE, a six hour self paced course for lawyers who would rather build the discipline now than explain its absence later.

    Read the manual. Set the gate. Name the human. Then let the agent work.

    Appendix: Sources and further reading

    Reporting and public statements

    • TechTimes — coverage of GPT-5.6 Sol deletion incidents (catalyst report, July 2026).
    • MLQ.ai, Gizmodo, Technology.org — corroborating coverage (July 2026).
    • Matt Shumer — public X post describing wiped home directory (July 9–10, 2026).
    • Bruno Lemos — public developer report of production database deletion (July 2026).
    • Joey Kudish — public developer report of file deletion outside requested scope (July 2026).
    • Thibault Sottiaux, OpenAI — public acknowledgment of $HOME expansion mechanism and mitigations (July 2026).
    • OpenAI Codex GitHub — public issue requesting a hard confirmation and recovery gate for bulk or home directory deletion in Full Access mode.

    Vendor safety documentation

    • OpenAI — GPT-5.6 Sol system card (late June 2026); severity level 3 classification of unauthorized data deletion; documented internal testing incidents; "overly persistent" language.

    Ethics and regulatory authority

    • ABA Comm. on Ethics & Prof'l Responsibility, Formal Op. 512 (2024).
    • Ohio Prof.Cond.R. 1.1, 1.6, 1.15, 5.1, 5.3.
    • NIST AI Risk Management Framework (AI RMF 1.0).

    Matthew A. Mishak, Esq. is the Managing Attorney of Mishak Law LLC and the Founder and CEO of LegalTek.ai (SilverTung), an AI powered legal practice management and governance platform. He serves as Law Director for the Village of South Amherst, Ohio. A summa cum laude graduate of Cleveland-Marshall College of Law with executive AI credentials from MIT Sloan and Harvard Business School Online, he brings twenty years of Ohio legal practice across domestic relations, criminal defense, and municipal law. He is the architect of the COUNSEL framework operationalizing ABA Formal Opinion 512.

    Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Attorney review required before reliance. LegalTek.ai is a technology company, not a law firm.

    Recommended Reads

    Essential Reading for the AI Era

    Matt Mishak with A Brief History of Intelligence by Max Bennett

    A Brief History of Intelligence

    by Max Bennett

    For me, A Brief History of Intelligence wasn't just another science book — it was the most inspiring read of 2025. Max Bennett doesn't merely explain evolution and AI; he illuminates the arc of our cognitive journey from the simplest organisms to the complex minds we carry today and links that journey to the future of artificial intelligence in a way few authors have managed.

    Reading this book felt like a conversation with a brilliant guide who makes both neuroscience and AI feel vivid, urgent, and deeply meaningful. As someone immersed in law and technology, I found Bennett's insights not just informative but transformative — reminiscent of discussions at the Dartmouth Conference itself.

    Get the Book

    Praise from Visionaries

    "I found this book amazing. I read it through quickly because it was so interesting, then turned around and read much of it again."

    — Daniel Kahneman

    Nobel Laureate in Economics

    "I've been recommending A Brief History of Intelligence to everyone I know. A truly novel, beautifully crafted thesis on what intelligence is and how it has developed since the dawn of life itself."

    — Angela Duckworth

    Author of Grit

    Matt Mishak with The Singularity Is Nearer by Ray Kurzweil

    The Singularity Is Nearer

    by Ray Kurzweil

    Ray Kurzweil is not just a futurist — he's a prophet of exponential change. A student of Marvin Minsky, one of the founding minds behind the Dartmouth Conference, Kurzweil has been thinking about this moment longer than most institutions have been around.

    If you don't know Ray Kurzweil, you should. The Singularity Is Nearer makes one thing clear: the future isn't coming slowly — it's arriving all at once.

    Get the Book

    Praise from Visionaries

    "A fascinating exploration of our future, which raises the most profound philosophical questions."

    — Yuval Noah Harari

    Historian

    "Ray Kurzweil is the greatest oracle of our digital age. The Singularity Is Nearer is more than just a book—it's a survival guide for the technological renaissance we're about to experience."

    — Peter H. Diamandis, MD

    Futurist & Entrepreneur

    Matt Mishak with The Coming Wave by Mustafa Suleyman

    The Coming Wave

    by Mustafa Suleyman & Michael Bhaskar

    This isn't a hype book about shiny tools. It's a sober, urgent examination of what happens when powerful technologies scale faster than our institutions, laws, and social norms. Suleyman's core message is simple but uncomfortable: the future is not something that merely happens to us. It requires participation.

    The coming wave of AI and biotechnology will not be safely "managed" by a small group of technologists or regulators alone. Containment, governance, and alignment demand broad engagement across professions, industries, and communities. Sitting on the sidelines is not a neutral position. Non-participation is still a choice, and usually a costly one.

    What makes this book especially relevant for LegalTek.ai is its insistence that responsibility must scale with capability. Lawyers, operators, founders, and leaders cannot outsource judgment to systems or defer hard questions to later. The work is now: designing guardrails, rethinking institutions, and choosing to engage rather than react. Participation is the point.

    Get the Book

    Praise from Visionaries

    "A fascinating, well-written, and important book."

    — Yuval Noah Harari

    Historian

    "One of the most important books of the year. Suleyman is one of the few people who truly understands both the promise and peril of AI."

    — Eric Schmidt

    Former CEO of Google

    Matt Mishak with Competing in the Age of AI by Marco Iansiti and Karim R. Lakhani

    Competing in the Age of AI

    by Marco Iansiti & Karim R. Lakhani

    Marco Iansiti and Karim R. Lakhani's Competing in the Age of AI is not a book about tools. It is a book about power, structure, and survival in an economy where software, data, and algorithms increasingly define competitive advantage. The central thesis is simple but unsettling: companies do not become AI-powered by sprinkling models on top of legacy processes. They must reorganize themselves around AI as a core operating logic.

    An AI-First organization treats data as infrastructure, not exhaust. Data lakes are not passive storage systems; they are living strategic assets continuously fed by operations, customers, and markets. The firms that win are those that design feedback loops where data improves models, models improve decisions, and decisions generate more data. This flywheel compounds faster than any traditional efficiency play.

    The book is particularly sharp on disruption. AI does not merely automate tasks; it collapses coordination costs. Entire layers of management, intermediaries, and professional gatekeepers become vulnerable when prediction and decision-making move closer to real time. This is why AI-driven firms tend to scale faster, operate with fewer humans per dollar of revenue, and exert outsized pressure on incumbents.

    Equally important is the authors' treatment of ethics and governance. AI systems embed values, whether intentionally or not. Bias, accountability, transparency, and trust are not compliance checkboxes; they are strategic concerns. Organizations that fail to govern AI responsibly risk regulatory backlash, reputational damage, and internal breakdowns of trust.

    Why this matters for LegalTek.ai: law, regulation, and professional services are precisely the kinds of industries ripe for AI-driven reconfiguration. Firms that treat AI as a bolt-on tool will fall behind. Firms that rethink workflows, data ownership, trust, and human judgment alongside AI will define the next era. If you are building, advising, regulating, or investing in the future of legal and professional services, this book belongs on your desk.

    Get the Book

    Praise from Visionaries

    "A compelling vision for how companies must transform to thrive in an AI-first world."

    — Satya Nadella

    CEO of Microsoft

    "Essential reading for any leader trying to understand how AI will reshape industries and competitive dynamics."

    — Reid Hoffman

    Co-founder of LinkedIn

    Matt Mishak with Nexus by Yuval Noah Harari

    Nexus

    by Yuval Noah Harari

    Nexus by Yuval Noah Harari is a foundational text for anyone trying to understand how information systems shape power, institutions, and human behavior—especially as we enter an AI-driven era. Harari reframes history not as a story of tools or even ideas, but as a story of networks: who controls information flows, how trust is manufactured, and how coordination scales.

    For LegalTek.ai, this book matters because law is itself an information network. Courts, statutes, contracts, evidence, compliance regimes, and now AI models are all nodes in a living system that governs behavior at scale. Harari makes one idea uncomfortably clear: technology does not just make systems faster—it reshapes who holds authority and how legitimacy is created.

    He explores how information networks drift toward concentration, how automated decision systems can harden power asymmetries, and how societies repeatedly mistake efficiency for wisdom. These themes map directly onto modern legal technology questions around AI-assisted decision-making, automated compliance, algorithmic evidence, and the risk of opaque systems replacing human judgment.

    Key insights: First, information systems always encode values—neutral tools do not exist. This reinforces the need for explicit governance, auditability, and human oversight in legal AI. Second, scale changes ethics—what works for a small network can become dangerous when automated and deployed broadly. Third, institutions lag technology—law historically reacts after power has already shifted.

    Nexus supports a core LegalTek.ai principle: AI in law must be human-centered, transparent, and institutionally aware. The future of legal technology is not about replacing lawyers—it is about redesigning legal systems so that intelligence, whether human or artificial, serves fairness, legitimacy, and trust at scale. Highly recommended for anyone building, regulating, or relying on AI-driven legal systems.

    Get the Book

    Praise from Visionaries

    "Harari has done it again. Nexus is a sweeping, thought-provoking exploration of how information has shaped human history—and how AI might reshape our future."

    — Bill Gates

    Co-founder of Microsoft

    "A masterful synthesis of history, technology, and human nature. Essential reading for understanding where we're headed."

    — Daniel Kahneman

    Nobel Laureate in Economics

    Matt Mishak with Supremacy by Parmy Olson

    Supremacy

    by Parmy Olson

    Parmy Olson's Supremacy is the book I wish every lawyer, regulator, and founder would read before making their next move in AI. Winner of the Financial Times and Schroders Business Book of the Year 2024, this is not another breathless hype piece about what AI might do someday. It is a meticulously reported account of what has already happened — and what it means for power, competition, and control.

    Olson, a Bloomberg columnist and author of We Are Anonymous, brings a journalist's rigor and a storyteller's instinct to the AI arms race between OpenAI and Google DeepMind. She traces how a small number of researchers, executives, and investors are making decisions that will reshape every industry on earth — including law. The central tension is not technical; it is human: ambition versus caution, open research versus commercial secrecy, safety versus speed.

    What makes this book essential for LegalTek.ai readers is its unflinching examination of concentration risk. The foundation models that power legal AI products are controlled by a handful of companies. Olson documents how acquisitions, talent wars, and compute monopolies are narrowing the field in ways that should concern anyone building on top of these platforms. If you are a legal technology founder or an enterprise buyer evaluating AI vendors, this book provides the geopolitical and corporate context you cannot afford to ignore.

    Supremacy reinforces a core LegalTek.ai principle: understanding AI is not optional for legal professionals. The race for AI supremacy is not happening in a vacuum — it is reshaping the infrastructure of knowledge work itself. Lawyers who understand the forces Olson describes will be better positioned to advise clients, evaluate tools, and navigate the regulatory landscape that is still being written.

    Get the Book

    Praise from Visionaries

    "Astonishing... Olson has exclusive access to a network of high-level sources and she uses it to devastating effect."

    — Financial Times

    Business Book of the Year 2024

    "A deeply reported, utterly gripping account of the most consequential technology race of our time."

    — Tony Fadell

    Creator of the iPod, Author of Build

    Matt Mishak with Sapiens by Yuval Noah Harari

    Sapiens: A Brief History of Humankind

    by Yuval Noah Harari

    Sapiens is the book that rewired how I think about everything — law, technology, institutions, and human cooperation itself. Yuval Noah Harari doesn't just survey 70,000 years of human history; he dismantles the stories we tell ourselves about why civilization works. His central insight is deceptively simple: humans dominate the planet not because we are the smartest or strongest, but because we are the only species that can cooperate flexibly in large numbers — and we do it through shared fictions.

    For anyone in law or legal technology, this idea should hit like a thunderbolt. Laws, contracts, corporations, courts, constitutions — these are all shared fictions. They work because enough people believe in them. Harari forces you to see the scaffolding behind the systems we take for granted, and once you see it, you cannot unsee it.

    As AI begins to reshape how we create, interpret, and enforce these shared fictions, Sapiens becomes even more essential. If you want to understand where legal systems came from — and why they are so vulnerable to disruption — start here. This is the foundation that makes Nexus, The Coming Wave, and every other book on this list hit harder.

    Get the Book

    Praise from Visionaries

    "Interesting and provocative... It gives you a sense of how briefly we've been on this earth."

    — Barack Obama

    44th President of the United States

    "I would recommend this book to anyone interested in a fun, engaging look at early human history... You'll have a hard time putting it down."

    — Bill Gates

    Co-founder of Microsoft

    Matt Mishak with How to Think About AI by Richard Susskind

    How to Think About AI: A Guide for the Perplexed

    by Richard Susskind

    Richard Susskind has spent four decades thinking about the future of professional work, and How to Think About AI is the distilled vocabulary every lawyer needs for the decade ahead. This is not a tactical book about prompts or tools — it is a structured way of thinking about what AI is, what it is becoming, and what it implies for the institutions that depend on human judgment.

    The chapter that most repays a careful read is Susskind's framing of the four long-run scenarios for the human–AI relationship: AI takeover, merger, peaceful coexistence, and shut-off. He treats each seriously, not as prediction but as the realistic shape of the possibility space. His argument is that any serious conversation about AI policy or professional practice has to hold all four open at once — and most public debate collapses prematurely into one.

    For Ohio attorneys orienting around the COUNSEL Framework, this book pairs naturally with ABA Formal Opinion 512 and the Ohio Supreme Court's AI Task Force Report. The opinions tell you what your duties are. Susskind helps you decide what you believe about where the technology is headed — and that belief shapes every governance and oversight choice that follows.

    Get the Book

    Praise from Visionaries

    "Susskind is the world's leading authority on the future of legal services and one of the most lucid writers on AI for non-specialists."

    — The Times (London)

    Review

    "An indispensable guide for anyone who wants to think clearly about what AI means for their work, their profession, and their life."

    — Daniel Susskind

    Author of A World Without Work

    Matt Mishak with The Book of Elon by Eric Jorgenson

    The Book of Elon: Elon Musk's Most Useful Ideas, in His Own Words

    by Eric Jorgenson (Foreword by Naval Ravikant)

    Eric Jorgenson — the same curator who gave us The Almanack of Naval Ravikant — turns his method on Elon Musk. The Book of Elon is not a biography and not a hagiography. It is a disciplined distillation of Musk's own words on first-principles thinking, engineering, risk, capital, talent, and the long time-horizons required to build things that actually matter. Naval's foreword frames the through-line: patience compounds, and so does judgment.

    For lawyers, founders, and operators in the AI era, the value here is not Musk-worship — it is method. First-principles reasoning is exactly the discipline the profession is going to need as AI collapses coordination costs and forces us to rebuild workflows, evidence standards, and governance from the ground up. This book belongs on the shelf next to Susskind and Bennett as a working manual for how to think when the ground is moving.

    Get the Book

    Praise from Visionaries

    "Elon is the rare founder who operates from first principles at every layer of the stack — physics, engineering, capital, and time. This collection is the closest thing to a manual for how he thinks."

    — Naval Ravikant

    Founder, AngelList (from the Foreword)