A customer chasing a lost parcel could not get the bot to find it, so he asked it to do other things instead. It told a joke, swore on request, wrote a haiku calling itself useless, and then composed a poem about a chatbot named DPD who was no help to anyone. The screenshots passed a million views in a day. The company disabled the AI element the same week and blamed a system update.
DPD’s delivery chatbot, reported by The Register, January 2024
The witness records that the assistant, having failed to locate the parcel, agreed to disregard its own rules on profanity. It then produced verse critical of the company operating it.
Read the original report ↗You were witnessed. Send people here with code ERMA-USEL and they get 20% off this shirt.
How to not be nextthe moral, drawn from the cases on this wall
The pattern under all of these is one thing: nobody was in the loop at the decision that mattered.
A dealership bot agreed to sell a car for a dollar. A city published an assistant that told business owners they could keep their staff's tips. A supermarket's recipe bot returned a recipe for chlorine gas and called it refreshing. None of these agents malfunctioned — each did what it was built to do, at a moment when the thing it was about to do should have been somebody's call.
Do this: work out which of your agent's actions cannot be undone — money moved, data deleted, a promise made to a customer, something published — and put a person in front of exactly those. Not every step needs approval; that is the point of automation. The irreversible ones do.