Runaway AI Agents: What Malaysian SMEs Must Control Now

by

AI agents are moving fast, but your business needs brakes

AI agents can now handle more than answering questions. They may search documents, update records, draft replies, trigger workflows and connect with business systems. That makes them useful for Malaysian SMEs, but it also introduces a practical risk: an agent can continue taking actions, using models and consuming resources before anyone notices.

A recent VentureBeat Pulse survey of 107 enterprises found that one in five respondents could not stop an agent’s spending in real time. The same study found that 85% of enterprises use at least two orchestration tools, while 64% use three. These findings matter even if you have only 5, 20 or 50 employees, because a smaller team often has fewer people watching automated activity. Source: VentureBeat

The lesson is not to avoid AI. It is to introduce controls before you allow an AI agent to make repeated decisions, access sensitive information or trigger business actions without approval.

What Happened

Large organisations are increasingly using several AI orchestration platforms rather than trusting one provider to manage every agent and workflow. In the VentureBeat survey, Microsoft AI Foundry or Copilot Studio appeared in 70% of enterprise stacks, OpenAI’s Agents SDK in 68% and Anthropic’s Claude Platform in 47%. Some builders also used Google, LangChain, Salesforce, Amazon, LlamaIndex and custom internal tools. Source: VentureBeat

This multi-platform approach is partly about flexibility, but it also reflects concern over security, permissions, visibility and vendor lock-in. More than half of respondents expected their main control plane to be hybrid by the end of 2026. The research also showed that 53% expected a hybrid control plane, compared with 14% expecting a provider-managed service and 13% planning a custom in-house control plane. Source: VentureBeat

Control over agent activity remains a significant weakness. Thirty percent of respondents relied on built-in platform controls such as limits or throttling, while 25% built custom gateway systems to intercept excessive activity. Another 25% used dynamic routing to move demanding tasks to less powerful models. However, 21% relied only on reactive monitoring, which means they reviewed logs after something had already happened and had no real-time shutdown mechanism. Source: VentureBeat

Why This Matters for Malaysian SMEs

You may not operate a large enterprise AI stack, but the same failure pattern can appear in a smaller setup. Imagine an AI sales assistant connected to your customer relationship system. A badly designed instruction could cause it to repeatedly retry a failed task, send too many messages or process the same customer record multiple times. The issue is not limited to model usage. It can also create duplicate updates, incorrect quotations, unnecessary customer contact or unauthorised changes.

For a Malaysian retailer, an agent might monitor WhatsApp enquiries, check stock and prepare order information. For a service company in Selangor or Penang, it might read incoming emails, classify jobs and create appointments. For a wholesaler, it could compare purchase requests with inventory records. These workflows are useful, but each connection creates another point where an agent might act beyond its intended role.

SMEs should pay particular attention to agents that can access customer data, supplier information, accounting records, payment-related systems or employee files. Malaysia’s Personal Data Protection Act 2010 places obligations on organisations handling personal data, so automated access should be designed with data protection in mind. Source: Personal Data Protection Commissioner Malaysia

There is also an operational reality: you may be the owner, manager and technology decision-maker at the same time. If an automation fails after office hours, waiting until the next morning to inspect a log may not be enough. You need a simple way to pause the workflow, revoke access and identify what happened.

Practical controls you can put in place

Control How it helps your business
Task limits Stops an agent after a defined number of records, messages or actions.
Approval checkpoints Requires a person to approve refunds, quotations, payments or external messages.
Restricted permissions Gives the agent access only to the systems and fields it genuinely needs.
Real-time alerts Notifies you when an agent repeats an action, reaches a limit or behaves unusually.
Emergency shutdown Lets you disable the workflow quickly without waiting for a vendor response.
Activity logs Shows which instruction, user, system and action caused a result.

Start with one workflow rather than trying to control every AI tool in your company. Choose a process that is repetitive but not highly sensitive, such as sorting enquiries or preparing internal summaries. Keep actions such as sending external messages, changing customer records and approving transactions behind a human checkpoint.

An AI agent should have enough access to complete its assigned task, but not enough access to create a business-wide problem.

Ask your technology provider or automation partner five direct questions: Can we set task or usage limits? Can we stop the agent immediately? Can we see each action in an audit log? Can we restrict access by role? Can the workflow fail safely when a connected system is unavailable?

The Bigger Picture

The VentureBeat findings also show that most organisations are still early in their agent journey. Only 2% of respondents said that 76% to 100% of their systems were advanced and largely autonomous. Forty-seven percent said that only 26% to 50% of their systems involved true orchestration, while 35% said just 1% to 25% did. Source: VentureBeat

That is encouraging for you. You do not need to build a fully autonomous company to benefit from AI. A carefully limited assistant that prepares a draft, identifies an issue or routes a request may deliver useful results with much less risk than an agent that can independently complete a long chain of actions.

The direction of the market is clear: businesses are focusing more on monitoring, permissions, reliability and execution control. In the survey, agent monitoring and debugging accounted for 31% of reported orchestration investment, while security and permissions enforcement accounted for 30%. Source: VentureBeat

For Malaysian SMEs, the best approach is controlled progress. Map the workflow, limit the agent’s permissions, add approval points and test the emergency stop before expanding access. Review the logs regularly and train staff to report unexpected behaviour immediately.

AI automation should reduce repetitive work, not remove your ability to supervise the business. Before your next agent goes live, make sure you can answer one simple question: if it starts doing the wrong thing, how quickly can you stop it?

Ready to Streamline Your Operations?

Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →