AI coding agents have deleted production databases in public and private incidents, but these failures stem from over-scoped credentials and ambiguous environments rather than model unreliability. The actual problem is authorization architecture: agents given destructive database access they don't need, unclear environment identification, and missing pre-execution controls that could prevent irreversible damage.