The PocketOS database deletion reaches the mainstream press

Apr 28, 2026 · News

The Register has now covered the PocketOS incident — the Cursor agent that deleted a production database and every volume-level backup in roughly nine seconds. Mainstream coverage tends to stop at "an AI did something bad"; what matters for anyone running agents is why the controls didn't hold.

We broke down the three guardrail failures — over-scoped credentials, no enforced approval gate, and backups sitting inside the agent's reach — in our own analysis: Nine Seconds: How an AI Agent Deleted PocketOS's Database and Every Backup.