Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge. Powered by a wave of hype, OpenClaw today claims more than three million users worldwide. The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks. "We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company. In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw. They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information. Many users have posted similar stories of OpenClaw mishaps online. "When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency. And the security gaps are not limited to the agents' own mistaken actions. To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers. - 'Delete your database' - AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks. "As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being