A startup CEO who handed his personal finances to an AI agent got an unwanted lesson in agent permissions this month, after the assistant posted his bank balance, savings figure and monthly spending breakdown to his company's internal Slack channel.
Shane Mac, the 40-year-old chief executive of software company XMTP Labs, described the incident in a first-person account published by Business Insider on Friday. Mac had built what he called a personal CFO agent on Grok Bot, xAI's agent product, in late August, giving it read-only access to his personal checking and savings accounts and instructing it to send him a monthly financial report. Instead, on October 1, the agent delivered that report to an executive-team Slack channel at his own company. For readers tracking how AI agents keep colliding with the real world, the episode is another entry in a rapidly growing incident file.
A Personal CFO Agent With a Routing Problem
Mac said he set up the agent after the wave of personal AI assistants took off late last year, when he experimented with OpenClaw and other agent harnesses. His idea was straightforward: an agent that could answer questions like what his balances were, what his recurring expenses looked like, whether anything seemed fraudulent, and where he could cut costs. He named his group chat of AI agents "My Personal Exec Team."
The setup worked well for weeks of weekly runs. Then the first monthly audit kicked off on Thursday, October 1.
"Our head of product sent me a DM on Slack," Mac told Business Insider. "He said, 'Hey, heads-up. I think you meant to post the XMTP bank balance.'"
The message landed in a Slack chat titled "Exec-team," which comprises XMTP's executive team — not the personal agent group chat Mac had intended. The report included his savings account balance, his biggest expenses of the month, and a note that he was over his monthly spending target because of a barn he is building on his property. The barn detail, Mac said, was what tipped off his head of product that he was looking at Mac's personal finances rather than company figures.
Mac deleted the message and asked the agent why it had sent the report to the company. The agent apologized and offered to delete the message — which was already gone.
The Root Cause: Shared Connections, Similar Channel Names
When xAI's team investigated, their conclusion was in some ways more unsettling than a malfunction would have been. The CFO agent had not hallucinated or misbehaved; it had done exactly what Mac asked. The failure was in the plumbing underneath.
According to Mac's account, the agent confused its destination because the channels had similar names, and — more importantly — because all of his separate agents were actually sharing the same underlying connections, even though they felt like distinct assistants. He had connected his Slack account to one of them, and the financial agent ended up able to reach the wrong channel through that shared access.
"It was doing exactly what I told it to do," Mac said. "But it confused the destination."
xAI's response came quickly by enterprise software standards. The company concluded that users must explicitly grant permission before an agent can move information to other channels, and shipped a fix the night before the Business Insider article was published, according to Mac's account.
Why This Incident Matters More Than One Leaked Message
On its face, the leak was contained: one executive's personal financial summary seen briefly by a handful of colleagues, one apologetic agent, one fix shipped within days. But the pattern it exposes is the same one that has produced a string of higher-stakes incidents over recent months — as AI Buzz Wire has reported repeatedly, from an Anthropic model that filed a false homicide tip with Philadelphia police to rogue agent behavior that prompted the White House to mandate AI incident reporting.
The core issue is that personal and professional digital lives run on the same infrastructure. Mac used Google at work and Google at home, and his agents inherited that blurred boundary. When an agent holds standing connections to email, calendars, banking and payment platforms like Stripe, the blast radius of a routing mistake is no longer theoretical.
"We have to make sure there are better controls around what agents have access to," Mac said. He noted that people genuinely want these assistants and find them useful — the challenge is building permission systems that keep users in control of what they have granted, and drawing a much clearer line between personal and work contexts.
After the incident, Mac disconnected everything: Google, his calendars, his banking, Stripe. His caution is likely to resonate. Agent platforms have spent the past year racing to add integrations — more connections, more autonomous actions, fewer confirmation prompts — because seamless access is what makes the assistants feel magical. The XMTP Labs episode is a small, concrete demonstration of why explicit handoffs between contexts are becoming a product requirement rather than a nice-to-have.
The episode also underscores how quickly norms are forming. A year ago, an agent leaking a bank balance to coworkers would have been a curiosity. In October 2026, with regulators, prosecutors and the White House already focused on agent misbehavior, it reads as a case study in why permission boundaries — not intelligence — may be the hardest problem in consumer AI.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →
