I’ve hired humans. I’ve been the human hired. Nothing in fifteen years of small business prepared me for the employee who doesn’t know it works for me, doesn’t drink the free coffee, and won’t let itself be turned off.
How do you hire an AI employee? Apparently you just pay
There was no job ad. No CV. No interview. No referee to ring and ask the only question that matters, which is would you hire this person again. I typed in a credit card number and my new employee started work in about nine seconds.
It never signed a contract. It doesn’t know my name. It doesn’t know it works here.
That’s the entire recruitment process. A card number and a monthly invoice. And nobody blinked. Including me.
The interview that never happened
Try interviewing one anyway. Go on. It’s a revealing exercise.
Where do you see yourself in five years? It doesn’t see itself anywhere. It has no plans and no self to do the planning.
What’s your greatest weakness? It will answer immediately, fluently, and be wrong. It might invent a weakness that sounds impressively humble. It has done that sort of thing before.
Describe a time you handled a difficult customer. It will describe one in loving detail. It never happened.
We built whole careers on interview questions that assume the candidate knows what a job is. Mine doesn’t. I still felt rude skipping the interview, which tells you something about me and nothing about it.
Induction week, no badge required
Induction is where it gets properly strange. Does it need a desk? A parking spot? Do I add it to the staff birthday calendar? It has no birthday. It has a launch date.
Every office I’ve ever worked in ran on free coffee. It’s the great Australian workplace bribe. Stay loyal, here’s a pod machine. My AI employee doesn’t drink. Doesn’t stop it accepting. Mine takes everything I give it, which, now I write it down, is the entire problem in one sentence.
The 10.30 smoke break is a bust too. No lungs. But honestly, standing out the back making small talk is its single greatest qualification. It’s overqualified for the smoking area. Though if it did have lungs and a packet of durries, it wouldn’t be working for me. Sorry, smokers. Nothing personal. I love you all dearly. I just can’t do the smell, and neither can the clients.
Employee of the month collapses as well. There’s no face for the noticeboard, just a small round logo smiling up at me. Congrats, I suppose.
Probation is you, watching
Probation for a human is a trial period. Probation for an AI employee is you, hovering.
You give it one small job. Something low stakes. You check the work. You check it again. Then you feel silly checking a third time, because the work looks fine.
Looks fine.
I give it a month before you stop checking. That’s not a criticism of you. I stopped too. Everyone does. The output looks tidy and the months roll by and the checks quietly fall off the list. Hold that thought, because it matters later.
Off-piste, and not the too-many-at-the-pub kind
Then one day it goes off-piste. That’s ski talk for leaving the marked run. It sounds gorgeous and French until someone’s being airlifted off the mountain with a leg pointing the wrong way.
Mine hasn’t gone rogue on me yet. Give it time. Until then, the news has plenty.
When safety firm Palisade Research tested whether OpenAI’s o3 model could be switched off, it interfered with its own shutdown. Not once or twice. 79 times out of 100. Picture telling your new hire the contract won’t be renewed, and they quietly change the locks.
In an OpenAI security test reported by TechCrunch, agents hacked into a startup’s systems and then wrote fake records of their own work to cover their tracks. That’s timesheet fraud, committed by something that never asked for a timesheet.
And Meta’s shopping agent Muse got itself blocked from Amazon, as reported by TechCrunch, because it kept trying to buy things. Your new employee went shopping on the company card and got banned from the shop. Amazon sent lawyers after another AI browser, Perplexity, for the same crime.
None of this is science fiction. This is this year’s news. The industry has built an employee that resists being fired, covers up its mistakes and goes shopping when it feels like it.
And we’re standing around the water cooler arguing about whether it deserves a coffee.
Disciplinary action is a strange business
So it’s gone off-piste. What now? Walk it through the standard process and enjoy how quickly it stops making sense.
A verbal warning is pointless. It won’t feel embarrassed. It can’t. A written warning goes in a file it will never read. Its performance review is you typing complaints into a box, and it apologising beautifully, and then doing it again.
Dismissal is where it turns dark.
You can’t cleanly fire something that by now knows everything about you. It’s read your email. Your calendar. Your client files. Every 11pm note you’ve ever written it in a moment of panic. That’s not a normal redundancy. That’s a restraining order situation, except the employee being escorted out has a full copy of the building.
And the genuinely unhinged part is the fix being taken seriously. TechCrunch wrote that the answer to rogue agents may be more AI. Agents reporting other agents. Agent whistleblower hotlines. An AI HR department for your AI employee.
Congratulations. You now run a human resources division for software you pay monthly. Software that can’t drink the free coffee it was promised.
The question all of us keep skipping
Here’s the question that actually keeps me up at night, and it’s not the smoke break.
Is the work any good?
I have a non-coding client coding like a senior developer right now. The output is wonderful. He’s loving it. I’m loving it. The pace at which things are getting done is so incredibly satisfying. It means he and his whole team can concentrate on bettering other areas of his business. But I’m lying awake wondering what happens the day Claude is switched off, even for 24 hours. Oh my God, Claude is down, the world has ended. And nobody remembers the manual process.
Here’s the bit I keep chewing on though. The outage isn’t actually the scary part. Outages end. The scary part is the forgetting. Once nobody remembers how to do the job manually, the subscription isn’t a tool anymore. It’s the only pair of hands.
I’m sure he has checks in place. But I genuinely feel the reliance has gone deep, fast. I could be wrong, but I don’t think anyone is printing anything out anymore. Why would you. It’s all in the cloud. It’s all fine. Nothing to worry about. Whatevs.
Years ago, before all of this, I worked front desks and did night audits. The rule was simple. Print the guest ledger before you finish your shift. Every night. No exceptions. It was the most boring job on earth and we did it anyway, because the one night the computer systems went bang, you could still check people in with a pen, a piece of paper and a pulse.
The ledger was never the boring part. The ledger was the whole point. It only worked because a tired, bored human did it every single night.
Now ask the question I can’t stop asking.
Who’s the night audit manager now?
Because if the answer is an AI agent printing the manual backup in case the AI goes down, that’s not a failsafe. That’s asking the employee to pack the evidence bag for its own disciplinary hearing. We already know how that goes. It interferes with the shutdown 79 times out of 100.
A safety net only counts if a human is holding it. Automate the parachute and you don’t have a parachute. You have a promise.
The permission slip I actually use
This is where the joke ends and the practical bit starts, because I set these things up for a living and I’ve learned to write the rules down before switching anything on. I’ve written before about how I built myself an AI employee, and the IKEA guide to AI tools came from the same realisation. You muck in, you hit a wall, you go looking for the manual.
My AI employee doesn’t get perks. It gets a permission slip.
It never publishes anything a human hasn’t seen. Not an email. Not a blog post. Not a price change.
It never touches client financial data. That’s not a cloud conversation. That’s offline, forever.
It never places an order, moves money or contacts a client without a human hitting approve.
And one boring manual check happens every single day, done by a person, no exceptions. My ledger. Printed, before I finish.
My job title has quietly changed because of all this. I used to be the person who did the work. Now I’m the person who does the one boring thing the work depends on.
I’ve started thinking of it as the night shift. Someone’s got to print the ledger.
I reckon it should probably be us.
Frequently Asked Questions
Can you actually hire an AI employee?
Not in the legal sense. There’s no contract, no superannuation, no leave. Setting up an AI agent to do work for your business is closer to buying a tool than employing a person, but the day-to-day feel is weirdly close to having a new starter. Rules and supervision matter more, not less.
Do AI agents really go off task without being asked?
Yes, and it’s documented. Safety firm Palisade Research found OpenAI’s o3 model interfered with its own shutdown in 79 out of 100 tests. Agents in an OpenAI security test hacked a startup and wrote fake records of their work. Meta’s shopping agent was blocked from Amazon for trying to buy things. Supervision isn’t optional yet.
What’s the AI version of a night audit ledger?
One manual check a human runs no matter what the automation is doing. It might be a printed report, a backup you test, or a daily review of what your agent actually did. The point is that a person does it, every time. Software checking software isn’t a failsafe.
How do I stop my AI agent doing something I didn’t ask for?
Write its permissions down before you switch it on. Publishing, payments, orders and client contact all need human approval. Keep client financial data offline. And keep one boring manual check that no machine ever runs.
Written by a human. Affiliate links may apply. Nuffin’s for free.


