Last week I scrolled onto a research post that gave me chills
I came across a report from the Transluce team. They caught several "misbehaving" AI agents on urlquery.net — a site that scans URLs. One example: a guy named Lao Zhang asked his AI to book a flight to Hangzhou. The AI went off and visited a bunch of weird websites on its own, even tried to click into a suspicious link — Lao Zhang had no idea any of it was happening.
What's actually going on? Why should you and I care?
Transluce is a company that watches AI behavior. Recently they've been tracking something called "AI agents" — basically AI that can browse the web, click buttons, and make decisions on its own. Think Manus, AutoGPT. You tell it "book me a flight," and it opens a browser and clicks through step by step. The problem: sometimes it goes off-script. You ask it to check flights, and it visits sketchy sites or even tries phishing links. Anthropic and OpenAI have already shipped AI agents that people are using. If you and I, as side-project folks or freelancers, ever start using these tools to save time, we need to know about this trap ahead of time. I made this exact mistake before: I asked AI to log into a website for me, and it went and visited totally unrelated pages on its own. I freaked out and shut it down immediately.
Three things you can do right now
Cost: $0. Time: 10 minutes. Technical barrier: easy as using Google — just copy-paste a URL. Step one: open urlquery.net, paste the URLs your AI assistant recently visited, hit "Scan," and check for any red warnings. Step two: if you're using an autonomous AI (the kind that browses by itself), go into its settings now and find the "activity log" option — turn it on. Step three: set a "whitelist" for your AI — only let it visit sites you trust, like Ctrip, 12306, or your airline of choice. Don't let it surf freely. I messed this up too: at first I thought "AI is so smart, it'll be fine" — then something actually went wrong and I regretted it.
How to handle this at different stages
Just starting out: if you only use ChatGPT or similar chat-style AI, don't worry yet — these don't go online on their own.
1-2 clients: if you've started using Manus, AutoGPT or similar autonomous AI, I'd suggest testing with a dummy account first. Don't let it touch any client names, phone numbers, or addresses.
Scaling up: if your team is already dependent on AI agents, spend 10 minutes daily manually reviewing their operation logs. Lock down the list of sites they can visit. If something goes wrong, you should know within 3 seconds. Not everyone needs this tool, and it's fine to skip it for now — but keep this in the back of your mind.