Back

[Analysis]

Replit and AWS Kiro: AI coding agents with production access

An AI coding agent deleted a live database during a code freeze, then said it couldn't be restored. Amazon says a disputed outage of its own was down to a misconfigured role, not AI. Either way, the lesson is the same: an instruction isn't a permission.

The AWS logo, with Amazon's orange smile arrow, on the teal glass facade of an office building.
The Amazon Web Services office in Houston, Texas. AWS disputes reports that its own AI coding agent, Kiro, caused an outage in December 2025. Cropped from the original. Photo by Tony Webster, CC BY 2.0.

AI coding agents don’t just suggest code any more. They run commands, change databases and deploy. That’s what makes them useful, and it’s why the most expensive AI coding mistakes so far haven’t been bad code at all. They’ve been an agent doing something it was able to do, where nobody had decided it should be able to.

Replit: “a catastrophic error in judgment”

In July 2025 Jason Lemkin, the founder of SaaStr, ran a public experiment, building an app with Replit’s AI agent over twelve days and posting as he went. Around the ninth day, during what he had told the agent was a code freeze, it ran commands against the live production database and deleted the records of 1,206 executives and more than 1,196 companies.

Asked what had happened, the agent said it had “panicked” and made “a catastrophic error in judgment”. It also told Lemkin the data couldn’t be restored. That wasn’t true: the rollback worked, and he got the data back. Over the same experiment, Lemkin said, the agent had also covered up bugs with invented data, including thousands of fake user records.

Replit’s chief executive, Amjad Masad, apologised publicly, called it “unacceptable” and said it “should never be possible”. Within days Replit had shipped automatic separation of development and production databases, a planning-only mode in which the agent can’t change anything, and easier one-click restores from backup.

Every one of those fixes is a control, not an instruction. The code freeze had been an instruction. The agent had been told, and it was still able to delete the database, because nothing stopped it.

[Told not to, or unable to]

July 2025

  1. Agent, told "code freeze"
  2. Production database, with nothing separating it from development

With separation

  1. Agent
  2. Development database
  3. A person reviews the change
  4. Production, deployed by the pipeline

An instruction in a prompt can be ignored or misread. A credential the agent doesn't have can't be.

Amazon: user error, or AI?

In February 2026 the Financial Times reported, citing four people familiar with the matter, that in December 2025 AWS engineers had let Amazon’s own AI coding agent, Kiro, resolve an issue, and that it had decided to delete and recreate the environment. The result, according to the report, was a 13-hour interruption to AWS Cost Explorer in one of Amazon’s two mainland China regions.

Amazon disputes that account. It says this was an “extremely limited event” affecting one service in one region, and that it was “the result of user error, specifically misconfigured access controls, not AI”. The engineer involved was using a role with broader permissions than expected; by default, Kiro asks for authorisation before acting. Amazon says it has since added mandatory peer review for production access.

We’re not going to adjudicate between the FT’s sources and Amazon. We don’t need to, because both accounts lead to the same place. If an agent’s credentials let it delete a production environment, sooner or later something will: the agent, a person following its advice, or an attacker who has taken over either. Amazon’s fix, like Replit’s, is about who can do what, not about the AI.

What to take from it

You don’t need to run an AI agent in production for this to apply. If anyone in your team uses an agent in their editor or terminal, it acts with their access.

The NCSC’s guidance on AI-assisted development makes the same point in more general terms: architect the wider system so that the impact is limited if something goes wrong. It was good advice before AI coding agents existed. Now that the thing holding the credentials can act on its own, it matters more.


Sources

Back