I give an agent access to a folder on my computer, subfolders included, most working days. The agent reads what is there, processes it and writes results back, on and off through the day. This has become ordinary practice for me, something that was not the case two years ago.
Ten Agents at Once
A chatbot is one question, one answer, done. Agentic AI works differently. It takes an assignment, breaks it into steps on its own, chooses the tools each step needs and builds further agents to carry them out. While one agent works it can spawn others. Ten or fifteen parallel processes running at the same time is not unusual on my machine. If one hits a wall it builds the next step itself and keeps scaling until the task is finished. In the terminal the whole run moves faster than I can read it. What comes out the other end is usually right.
Work that would have taken me several days is often done a few minutes later. As a single subscriber, with no IT department and no server infrastructure of my own, one capable computer lets me work like a whole team of programmers. In a few days I have built full websites, knowledge bases, automated query systems and ontologies for whatever subject I need, drawing on outside sources and books and tying that context back to my own material. The speed and the precision still catch me off guard. Mostly in a good way.
What I Cannot Fix Mid-Run
Agents decide on their own because they have to work on their own, and even the newest models make the wrong call more often than the companies selling them admit. When that happens there is frequently no line of reasoning a person could follow back to the mistake. I found this out directly. More than once an agent has overwritten a finished text of mine, one I had spent real hours writing by hand, within minutes. The original was gone, not recoverable from a trash folder or a version history. I had to start over, and whatever time the agent had saved me on that task was lost with it.
A running agent process cannot be corrected. The only intervention available is to stop it entirely. If agent twelve of fifteen makes an error I cannot step into agent twelve and tell it to do the next part differently, and I cannot undo what it already did. Killing the whole run and starting again is the only option. I hand over control completely, and it returns only when the process finishes or I pull it. Either way, my own files can already be gone by then.
On small tasks none of this matters much. On large ones it does, and the tasks keep getting larger, because the whole setup invites bigger thinking. I feed in more data, give more context, allow more scope. Each larger task hands the agent the whole folder at once.
Whose Server, and Who Else Is Watching
The door I open each time is for an agent. What that agent does with what it finds, and who else might be behind it, rarely gets serious scrutiny. My files sit on my own drive, but the processing runs on the servers of an American company. What happens to the data there I do not know. Nobody outside that company knows. The models update constantly, and reading the privacy terms for each update was already a losing race before the volume of data now passing through got involved. I could look the terms up. It would not change how much moves through in how little time, on my side or on the terms of use.
The scale of what one hands over keeps escalating. A Google search was one word and a prompt a paragraph. An agent swarm now moves through thousands of files in a single session: texts, notes, folder structures, strategy documents. The agent gets whatever it needs, and with it the files leave the computer they were sitting on.
The same thing happens inside a company. An employee feeds everything in, enjoys the result and goes home. Neither IT nor compliance knows about it. The data is already outside. It is happening right now, in thousands of offices, at the same time. No security policy has caught up with what agents already do.
I grant this access every day and I know what I am doing each time I do it. What I keep asking myself is whether I actually understand what happens once I do, and whether the pace at which these agents multiply leaves any time to find out. I doubt it does.