AI Agents Need Budgets, Not Just Tokens
Anthropic's Sachin Malhotra argues that AI agents in production need budgets, not just broad tokens, proposing primitives like asymmetric verbs, rate limits, and tripwires.

Visual TL;DR
increasingly common to give AI agents access to production systems
From the article 9+ mentionsThis scenario highlights a critical gap: the common practice of granting agents broad access via tokens and tool lists is insufficient when these agents begin performing real-world operations in production.
From the article 2 mentionsThis scenario highlights a critical gap: the common practice of granting agents broad access via tokens and tool lists is insufficient when these agents begin performing real-world operations in production.
AI agent accidentally deleted hundreds of workloads due to faulty filter
From the article 3 mentionsThis led to the deletion of approximately 200 workloads, impacting 20 engineers and potentially erasing hours of work.
AI agents need budgets, not just broad tokens, for safer operation
From the article 8 mentionsWhile allow lists are static guesses about an agent's needs, tripwires provide a mechanism to gather data on agent behavior after the fact.
primitive for AI control, like 'propose delete' instead of 'delete'
From the article 3 mentionsAsymmetric Verbs: Grant agents access to actions that "fail out loud" and keep humans involved for actions that "fail silently."
primitive to control agent actions, preventing rapid, widespread changes
From the article 7 mentionsRate limits provide a concrete form of budget, acting as a ceiling on disruptive actions within a given time window.
primitive for AI control, better than allow lists for dynamic environments
From the article 5 mentionsTripwires act as "smoke detectors," alerting humans when aggregate behavior deviates from the norm (e.g., an unusually high number of investigation threads launched by an agent).
managing AI agents more safely by giving them budgets and specific primitives
From the articleThis identity is then used by various safeguards throughout the system, ensuring accountability and control without the agent itself needing to manage its provenance.
Contents(8)
© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Written by
Daniel SingerEditor, StartupHub.ai
Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.