Blog · AI

How autonomous you let AI agents be with customers

Since summer 2026, AI agents can browse and act on your behalf without asking for approval at every step — a real shift, not just a marketing one. The speed gain comes paired with a documented risk: prompt injection, meaning instructions hidden in external content that can hijack the agent. A simple framework, "Agents Rule of Two," helps any business decide how much autonomy it's actually giving an agent that talks to customers.

9minute read
2026-09-09published
AIcategory
Business owner checking a dashboard of automated customer conversations
AI
01

Why this question became urgent right now

The conversation about autonomous AI agents in customer relationships changed abruptly on 26 August 2026, when Anthropic moved Claude in Chrome — an agent that controls the browser — into general availability, and the real change wasn't the extension itself, but the fact that the agent can now execute actions without asking for approval at every single click. Until then, every step in an automated browsing flow required explicit human confirmation; from now on, the agent can chain multiple steps on its own, which means real speed, but also a much larger window for an uncontrolled mistake.

For a business weighing an AI agent in customer relations — on the site, in support, in order processing — this changes the basic question. It's no longer "can AI do this," because the answer is almost always yes, but "how much freedom of action am I giving, without human-in-the-loop oversight, to a system that talks directly to my real customers." It's a configuration question, not an abstract technical one.

02

The difference between an agent that "responds" and one that "acts"

A classic support chatbot replies with text — it explains a return policy, gives opening hours, suggests a product. A modern agent can go a step further: it actually opens the return page, fills out the form, sends a confirmation email, or even places an order with a supplier, without a human pressing any button in between. The difference looks small from the outside, but behind it lies real access to systems, not just a knowledge base it pulls text answers from.

For an online store, an agent "that acts" could process a return on its own, update stock based on an order received by email, or automatically reply to a negative review. For a restaurant, it could confirm a booking, automatically update the hours shown across several platforms at once, or send a follow-up message after a delivered order. All useful — and all with a different risk profile than a simple text chatbot.

03

The real risk behind it: prompt injection

Prompt injection means, in short, instructions hidden inside content the agent reads from outside — an incoming email, a web page, a customer review — that try to hijack the agent away from its original task toward an action the business owner didn't want. It isn't an abstract theory: the OWASP report dedicated to agentic applications shows that this type of vulnerability shows up in 6 of the 10 categories in their risk ranking, and out of a tracked sample of 53 real agentic projects, 28 were exactly the kind of tools used daily for code delivery and automation.

The reason this risk matters specifically for a support or operations agent, not just a coding one, is simple: any agent that reads content coming from customers, from the internet, or from incoming emails is, by definition, exposed to exactly the kind of content where a malicious instruction can be hidden. The more freedom of action the agent has over that content, the more real damage a well-placed hidden instruction can cause — not just a strange response shown on screen.

04

The practical framework: "Agents Rule of Two"

A simple decision framework, discussed increasingly often in the AI agent security community, splits any automated task into three possible ingredients: access to private business or customer data, exposure to unsafe content from outside, and the ability to communicate directly outward — sending an email, posting something public, placing a real order. The practical rule is easy to remember: a fully autonomous agent, with no human in the loop, should have at most two of these three ingredients at once, never all three together.

Applied to a concrete example: an agent that reads a company's support emails (private data) and replies directly to customers (external communication) can operate autonomously, as long as it isn't allowed to browse unsafe web pages freely or open unknown attachments (the third condition). The moment you also hand it that third ingredient, the rule is clear: that's where you need to add a human review step, not more unsupervised automation.

05

What this rule looks like applied to a shop or a restaurant

An agent that only reads public reviews and prepares a draft reply, later sent manually by someone on the team, follows the rule — it has exposure to unsafe content, but no automated external communication, because a human approves every message before publication. The same agent, left to publish review replies on its own without review, adds the third condition and becomes exactly the kind of setup the rule discourages, especially on a public channel visible to every future customer.

The table below sets side by side three common scenarios for a shop or a restaurant, with the actual ingredients present in each and the resulting verdict under the rule. The point isn't to memorize these exact three examples, but to learn the pattern of thinking — list the ingredients, count how many show up at once, and decide the checkpoint based on that number, not on a general impression of how "smart" the agent seems.

ScenarioIngredients presentDoes it need a human in the loop?
Draft reply to reviews, sent manuallyprivate data + unsafe contentno — the third condition is missing
Return processed automatically, from its own formprivate data + external communicationno, if the form is internal and controlled
An agent that browses the web and responds publicly on its ownall three at onceyes — mandatory, under the rule
06

Checklist before giving an agent access to real customers

Before activating any agent with real actions in customer relations, it's worth going through a short checklist, not just a quick test on a few successful conversations. An agent that performs well in ten controlled attempts can still hide a risky configuration for the eleventh case — exactly the unusual one nobody explicitly tested before launch.

The list below doesn't replace a broader security discussion, especially for businesses with a high volume of orders or sensitive customer data, but it covers exactly the points that get skipped most often in a rushed implementation. Each step generally takes a few minutes of thought — a small real cost compared to the time later lost fixing a misconfiguration discovered only after an incident.

  • 01List exactly what private data the agent touches — orders, emails, customer history.
  • 02List exactly what unsafe external content it's exposed to — web pages, reviews, incoming attachments.
  • 03List exactly what it can communicate externally on its own — email, a public post, a real order.
  • 04If all three show up at once, you must add a human approval step before the action.
  • 05Retest the configuration periodically — an agent update can silently add a new capability.
07

What you don't do, even though the technology genuinely allows it now

The natural temptation, once an agent performs well in tests, is to give it full access and remove every human-verification step, justified by the speed gained. That's exactly where the most common mistake appears: the absence of a verification step for irreversible actions — an order placed, an email sent to a customer, a public reply — not because the agent makes mistakes often, but because, when it does, no one catches the error before it reaches a real customer.

The rule worth remembering isn't "less automation," but "automation with a checkpoint wherever the consequence of a mistake is hard to undo." An agent can stay fully autonomous for preparation, analysis or drafting, and ask for human confirmation exactly at the moment of an irreversible action — a trade-off that keeps almost all the speed without fully removing the safety net.

08

Autonomy is a dial, not an on-off switch

The right question isn't whether you activate an AI agent in customer relations or not, but how much of that process stays under its control, unchecked. "Agents Rule of Two" gives a simple language to a discussion that otherwise stays vague — not "it's safe" or "it's not safe," but exactly what combination of access, exposure and external communication that agent has, today, in its current configuration.

The businesses that will really benefit from AI agents in customer relationships won't be the ones that gave them as much autonomy as possible as fast as possible, but the ones that built, from the start, a clear answer to the question "what exactly happens if this agent gets it wrong right now". It's a discussion that takes a few hours, not a few months, but it's worth having before launch, not after the first real incident with a customer.

09

Sources and further reading.

FAQ

Frequently asked questions

What is "prompt injection," explained for a non-technical reader?

A hidden instruction inside external content — an email, a web page, a review — that the AI agent reads and, without verification, can treat as a real command, diverting it from the task originally given by the business.

What exactly does "Agents Rule of Two" mean?

A practical framework stating that a fully autonomous agent, with no human in the loop, should have at most two out of three: access to private data, exposure to unsafe content, and the ability to communicate externally on its own.

Is a simple chatbot on a website just as risky as an autonomous agent?

Not necessarily — a chatbot that only replies with text, without acting on real systems, has a much lower risk profile than an agent that can fill out forms, send emails or place orders on its own.

What is Claude in Chrome, and why did the topic become relevant right now?

An AI agent that controls the browser, reaching general availability on 26 August 2026, with the ability to execute actions without approval at every step — the shift that brought the autonomy discussion to the forefront.

How do I test whether an AI agent is safe before activating it for real customers?

Explicitly list the three ingredients — private data, unsafe content, external communication — for the agent's exact task, and check whether all three show up at once, in which case you need a human approval step, no exceptions.

Does a human need to be in the loop for every single action an AI agent takes?

Not for every action, but for irreversible ones or ones with real risk — an order placed, a public message sent, an email to a customer. The rest of the process can stay fully automated without losing safety.

The Niche Society
The Niche Society TeamAI and software engineers from Bucharest · LinkedIn
published 2026-09-09

Let's see what can be automated in your business.

A free 30-minute session: we'll tell you what can be automated, how long it takes and what it costs, with a fixed price after discovery.

Book a free sessionoffice@thenichesociety.ro

We reply the same business day.

+40 733 045 833