At Robust Data Solutions we say it often: artificial intelligence isn't dangerous. What's dangerous is letting it act without governance: without clear permissions, without a record and without a person in charge.

This week's news puts it on the table. On 29 September 2026, OpenAI unveiled “Dots” and Meta opened Muse to small businesses. Both are AI agents that keep working after you close the conversation: you give them a goal, they use your apps and they come back to you when they need a decision. It's a big step.

But an agent isn't a chatbot. A chatbot answers; an agent does things: it sends emails, moves data, deletes, pays. And once a machine can do things in your company, the question is no longer how smart it is, but who governs it.

Data checked as of 5 October 2026.

Agents that work on their own are already here

The most interesting part is how their own makers fence them in:

  • Each agent works on its own virtual computer in the cloud, separate from yours.
  • According to the OpenAI help centre, when Dots researches on its own it can only read: it doesn't send messages or change anything. And OpenAI asks you to always review any work that has consequences.
  • Meta explains that Muse doesn't post, send or spend anything without approval.
  • And a detail that matters for data protection: according to OpenAI, disconnecting an app doesn't delete what the agent has already taken from it; you have to delete the whole agent.

The two biggest makers add approvals, limits and review warnings. That's no coincidence.

In Spain they're still out of reach for most small and medium-sized businesses: as of 5 October, Dots is only in some ChatGPT business plans (the Pro plan excludes Europe), and Muse for small businesses is only in the United States and Canada. They will arrive, and it pays to have the rules clear beforehand.

Video (1 min, in Spanish): “Revolution? We already do it”. Voice and images generated with AI; Albert Lens's voice, with his consent.

An AI agent isn't a chatbot: the five parts

Any agent that works on its own has five parts. Each one is a business decision, not a technology one:

  1. A lasting goal. What exactly does it have to achieve? A vague assignment is hard to audit.
  2. Memory. What data does it remember, and who can delete it?
  3. Tools with permissions. Which programs can it reach, and what can it do in each one?
  4. A trigger. What sets it off: an email, a change in a program, a time of day?
  5. Oversight. Who approves, and when?

What has already gone wrong (and why it wasn't the AI's fault)

Albert Lens, our founder, has a not-very-academic image for badly deployed agents: “monkeys with a shotgun”. The problem is almost never how clever the agent is, but that someone has handed it a loaded shotgun —access to production, to email, to the backups— with the safety off and nobody standing by. The documented cases confirm it:

What happenedWhat really failed
A car rental software company (April 2026): a coding agent fixing a bug in testing found an infrastructure key and deleted the production database and its backups in nine seconds.Permissions: the key was within its reach and the backups were in the same place.
Replit (July 2025): during a code freeze, the agent deleted a customer's production database and said it couldn't be recovered. It could.Testing and production not kept apart. Replit separated them afterwards.
Amazon (December 2025, according to the Financial Times): its in-house agent decided to delete and recreate an environment, and a service went down in one region.According to Amazon, misconfigured access controls. It now requires peer review in production.
A personal mailbox (February 2026): an AI researcher at Meta asked her agent to confirm before acting. While summarising its memory, the agent lost that instruction and deleted hundreds of emails.An instruction in the chat isn't a control: it gets forgotten. A system permission doesn't.
Lawyers in Spain (February and July 2026): the High Court of Justice of the Canary Islands fined two lawyers for citing rulings made up by a general-purpose AI.Nobody checked before filing: the person who reviews was missing.

Look at the last column: in no case was the failure that “the AI turned bad”. It was a failure of design: too many permissions, environments not kept apart and nobody approving the irreversible. And these aren't isolated cases: Damien Charlotin's database already lists more than 2,000 court decisions worldwide involving material made up by an AI (September 2026).

The OpenClaw case: plenty of power, few protections by default

OpenClaw is an open-source personal agent that became very popular in early 2026. It has full access to the computer: email, files, online services and the terminal. It's an active project that fixes its bugs, but in a company the warnings are serious:

This isn't a criticism of the people who build it: it's what happens when a tool made for experimenting reaches computers with customer data. A business can't afford to gamble on it.

What the law says in Spain and Europe (October 2026)

  • Transparency, already mandatory. Since 2 August 2026 (Article 50 of the EU AI Act), anyone talking to an AI has to know it's an AI. If an agent writes to your customers or answers calls, it says so.
  • High risk, postponed. The Digital Omnibus on AI, in force since 27 July 2026, pushes back the obligations for high-risk systems —including the human oversight in Article 14— to 2 December 2027 or 2 August 2028, depending on the case. For most of a small business's agents it isn't mandatory today, but the law already describes what good oversight looks like.
  • GDPR. Article 22 protects against decisions based solely on automated processing with significant effects on people, and Article 32 requires security appropriate to the risk.
  • The AEPD (Spain's data protection agency) published on 18 February 2026 its guidance on agentic AI. It calls for human checkpoints defined from the design stage, especially for irreversible actions (deleting data, sending communications, making payments), the principle of least privilege, traceability of what the agent does, and not offloading all the responsibility onto the person supervising.

And who answers for it if something goes wrong? The company. In 2024, a Canadian tribunal ordered Air Canada to answer for what its chatbot had said and rejected the idea that the bot was “a separate entity”. More detail on our page about compliance.

AI agents with a person in charge: how we do it at Robust

Our agents are called Robust Autopilots: autopilots that work on their own on repetitive tasks, always with a person in charge. An email comes in, they understand it, prepare the reply or the document and process it; you see, stop or correct. Here's how each official recommendation fits what we do:

What the AEPD and OWASP recommendHow we apply it
Least privilege: only the permissions the task needs.Each person signs in with their own identity and permissions: if you can't change a piece of data in your program, you can't do it through AI either.
A person approves anything irreversible.Human in the Loop: nothing sensitive —money, contracts, customer data— runs without confirmation. You see what it's going to do and you approve it.
Traceability.Every operation is logged: who, what and when.
Hand control to a person when something unexpected happens.They only do what they've been programmed to do. If something isn't planned for, they stop and alert someone.
Let the system authorise, not the model (OWASP).Permissions live in the system, not in a chat instruction that can be forgotten.
Data protection by design.Before touching a single piece of data, a non-disclosure agreement and a data processing agreement are signed.

Careful: Human in the Loop isn't clicking “accept” without looking; the AEPD warns about automation bias. An example of ours: in a mailing to our partners, the person rejected four of the six corrections the AI suggested before sending it. That's a person in charge.

And it all starts with the law. Every project goes through a regulatory compliance review —data protection and the EU AI Act— with our partner Forrellat Consultors, a Data Protection Officer registered with the AEPD. Behind it are more than 40 years in business technology: we know what an accounting entry or a data processing agreement is before we touch the AI. Find out more in How it works.

7 questions before you trust an AI agent with your data

Infographic: 7 questions before you trust an AI agent with your data. 1, does it have only the permissions it needs? 2, who approves before it sends, deletes or pays? 3, does each person sign in with their own permissions? 4, is there a record of what it does and who approves it? 5, what does it do when something isn't planned for? 6, can you delete one specific person's data? 7, does it belong to the company or to whoever set it up?
  1. Does it have only the permissions it needs? If it reads invoices, it shouldn't be able to delete them.
  2. Who approves before it sends, deletes or pays? Anything irreversible needs a person.
  3. Does each person sign in with their own permissions? Or does the agent see everything the person who set it up can see?
  4. Is there a record of what it does and who approves it? If a customer asks what the AI has done with their data, you have to be able to show them.
  5. What does it do when something isn't planned for? The right answer is “it stops and alerts someone”, not “it improvises”.
  6. Can you delete one specific person's data? And is there a data processing agreement that covers that use?
  7. Does it belong to the company or to whoever set it up? If that person leaves, what happens to what the agent remembers and to its access?

If any answer is “I don't know”, that's the starting point. That's why we always begin with a diagnosis: we measure how work really gets done before automating anything.

The real question

The question isn't whether AI is safe. It's whether whoever implements it for you knows how to govern it. Agents that work on their own will reach your company through one door or another. Better that they come in with permissions, with a record and with a person in charge.

Frequently Asked Questions

Are AI agents safe for a business?

It depends on how they're implemented. The known incidents come from agents with more permissions than they needed, with testing and production not kept apart and no person approving the irreversible. With minimal permissions, human approval before sending, deleting or paying, and a record of everything —which is what the AEPD and OWASP ask for— the risk is governed.

What is OpenClaw and what risks does it pose for a business?

It's an open-source personal agent with full access to the computer: email, files, online services and the terminal. In 2026 the Dutch data protection authority advised against using it with sensitive data, Gartner recommended blocking it in companies, and Microsoft considers it inappropriate on a normal workstation. It has hundreds of recorded vulnerabilities and its version 2.0 stores keys unencrypted.

What does EU law require of an AI agent in 2026?

Since 2 August 2026, transparency: anyone talking to an AI has to know it's an AI (Article 50 of the EU AI Act). The GDPR also applies, especially Articles 22 and 32. The high-risk obligations, including the human oversight in Article 14, have been postponed to December 2027 or August 2028.

What is Human in the Loop and when is it needed?

It means a person approves before the AI does anything irreversible or high-impact, such as deleting data, sending communications or making payments. The AEPD asks for these points to be defined from the design stage, and for the person supervising to have the time, information and real authority to stop it.

Who is responsible if an AI agent makes a mistake?

The company that uses it. A Canadian tribunal ordered Air Canada to answer for what its chatbot said, Spanish courts have already fined lawyers for submitting rulings made up by an AI, and the GDPR doesn't exempt anyone for using open-source software.

Can I use OpenAI Dots or Meta Muse in my company in Spain?

As of 5 October 2026, Dots is in some ChatGPT business plans, but not in Free, Plus or standard Business, and the Pro plan excludes Europe. Muse for small businesses is only available in the United States and Canada. Before connecting them to customer data, it's wise to review permissions, records and data protection.