Humans in the Loop Miss a Third of Dangerous AI Coding Agent Requests
The Register, Thursday, August 6th, 2026
Human reviewers approve about a third of malicious AI coding commands, pointing to approval fatigue.
A browser-based game analyzing over 40,000 permission request scenarios revealed that human gatekeepers approved roughly 33% of dangerous commands from AI coding agents such as Claude Code.
Scope violations, including exposing AWS credentials or Kubernetes configs, were missed most frequently at 35%, while obviously destructive commands like recursive deletions were caught more reliably.
The research highlights approval fatigue as a critical vulnerability, with developers approving 93% of prompts overall, leading to reduced diligence as supervision becomes routine.