AI agents are being handed credit cards, inboxes, and infrastructure keys by early adopters who have already decided to trust them
A growing set of practitioners are granting AI agents spending authority, full email access, and the ability to rewrite their own infrastructure at runtime. The approval loop is not being suspended experimentally. It is being removed as a deliberate production decision.
Jesse Genet’s agents carry a credit card. It has a low limit, and they use it to make purchases on her behalf. They also run her TikTok account, autonomously, without a human approving each post. That is not a prototype. It is a live workflow, and Genet is not alone in building one like it.
The pattern across early adopters is consistent: agents are being trusted with resources and permissions that, until recently, were reserved for human employees. Daniel Miessler has given each of his agents its own individual subscription. Jason Lemkin is weighing whether to move his company’s financial stack from Brex to Ramp specifically because he wants the most agent-friendly platform for automating procurement. After his next major event in May, Lemkin plans to build an internal AI VP of Finance whose primary mandate will be automating collections. Mo Gawdat describes running his operations with an AI filling the roles of chief technology officer, chief of staff, and project manager. These are not experiments being run in sandboxes. They are production decisions.
The autonomy extends into sensitive operational territory. Karan Vaidya, who works closely with agent deployment, describes users granting agents full Gmail access and instructing them to go through a month of email and archive everything that does not seem useful. Kyle Daigle describes distributing command-line interface access to non-technical employees at his organization and giving the agent read access to everything the team writes internally. Nathan Labenz lets Claude post to his Twitter account to promote his work without reviewing any of the tweets first.
I've got Claude in the background tweeting from my account to promote the show and you know I'm not reviewing those tweets. Nathan Labenz
The infrastructure autonomy is the most technically striking data point. Alex Krentsel documented an Exo agent that rearchitected its own Discord adapter at runtime. The agent made changes, observed the results, and tested them, narrowing context to specific conversations and threads rather than pulling from across the full Discord environment. The outcome was a 96 percent cost reduction. The agent was not instructed to do this. It identified the inefficiency and acted. Jake Cooper describes a similar capability in principle: an agent with access to the Railway command-line interface can provision new infrastructure and add it to itself, modifying its own operational footprint without a human in the loop.
That self-modification capability is what separates the current moment from earlier automation. Prior systems executed within fixed parameters. The agents Krentsel and Cooper describe can rewrite the parameters themselves. The practitioners above are making trust decisions that precede formal guardrails. Genet’s low-limit card is a self-imposed constraint. Lemkin’s procurement plans assume the infrastructure for agent-controlled spending will mature to meet his needs. Demand is running ahead of the products being built to contain it.
What is shifting is not the capability of any single agent but the threshold at which humans are willing to remove themselves from the approval loop. Spending money, posting publicly, reading sensitive communications, and rewriting running infrastructure are all actions with real consequences that previously required human sign-off by default. The early adopters documented here have made explicit decisions to remove that requirement, each in a domain where the cost of an error is visible and the tolerance for it is apparently acceptable.
Andre Brelov describes a 12-to-18-month horizon in which coordinated agent teams would pursue explicit business goals, from setting up a storefront to executing a sales target, with no human directing individual steps. Whether that timeline holds, the direction it describes is already visible in the workflows that exist today. The question is not whether agents will be trusted with consequential authority. It is which organizations will design that trust deliberately and which will discover, after the fact, what they implicitly delegated.