When an AI agent retries a task, it should try something different each time, not the same step over and over with more force. Set limits on steps, time, and money before you start, watch the first run yourself, find the Stop control before you begin, and keep the actions that send or delete things switched off until a person approves them.
Say you start an AI agent on your laptop before your coffee is ready. You ask it to download last quarter’s product catalog from a partner’s website, a zip file of about 18 MB, because you need it for a nine o’clock recap. You go to pour the coffee. By the time the mug is full, your Downloads folder holds 23 files, each 168 MB, and none of them is a real zip.
A retry is one new tactic
A retry is useful in itself. Networks flake, a content delivery network (the servers that hand out a site’s files) hiccups, and a vendor page throws a temporary error and then comes back. You would try once more too, and the agent does the same job, only faster and without any sense of embarrassment. The useful version tries a different move, such as a second URL, a smaller file, a short wait, or a question to you. The runaway version repeats the same fetch and saves it under a new filename, because the browser’s default is not to overwrite an existing file.
In the scene above, the 23 attempts were one tactic with a counter attached. The agent used the same partner URL and got the same “access denied” page in disguise, and each time it reported the same “could not extract” result. Every miss saved another 168 MB file that was not a zip, and the operating system numbered them (1) through (22), so the folder looked busy. Busy is not progress. Progress is a file whose size matches the catalog (about 18 MB) and that opens into spreadsheets.
The same pattern shows up on a login wall, a CAPTCHA (the puzzle that checks you are human), a two-step sign-in prompt, or a permission sheet you did not click. The agent reads “access denied,” invents some hope, and clicks again. Meanwhile you are in the kitchen, and the dialog just sits there, or an Allow button is within reach and downloads keep stacking up. Anthropic’s help pages for Claude Cowork are blunt about it: watch for unexpected patterns, and if something feels off, stop the task. Check where the Stop button is the week you run the task, because vendors rename it.
Rule of thumb: The same error twice is a stop. A retry needs a new tactic or a human, not a higher attempt count.
Write that rule into your first message if the product has no retry setting. Coding agents and developer kits often expose the same idea as a turn cap, with names like max_turns or max_iterations. Everyday tools such as Cowork or ChatGPT’s agent mode may not show any number at all, so the limit has to live in your prompt or it does not exist.
Three caps before the first run

The earlier post in this series explained the basic agent loop: set a goal, make a plan, take an action, look at the result, and repeat. This figure adds a budget at the start and a way to stop at the end. You say what “done” looks like, you set three numbers, the agent acts once, you look at the folder or the log, and you allow a retry only if the result changed. In our scene you skipped the numbers, so the loop had nowhere to end except your hard drive.
Cap the steps. Count tool calls, not sentences. One zip from a known URL is 4 to 8 actions, once you include listing the Downloads folder and checking the file size. A first run on a new vendor site should stay near 8. If the product will not show a counter, paste stop after 8 actions and watch the log. When the log reaches 8 and the zip still is not about 18 MB, you are finished for this sitting.
Cap the time. An 11-minute coffee is already too long for a first fetch you have never watched. Six minutes is a generous kitchen timer for one file. Scheduled Cowork tasks keep running when the laptop lid is closed, and Anthropic says so in its safety article, so do not schedule a download-and-retry until you have seen it finish once with you in the chair.
Cap the spend. Agent loops use up your plan’s allowance. Some ChatGPT plans count agent-style runs against a monthly or weekly pool (check your plan’s help page for the current rule), and paid developer access charges dollars per call. A stuck loop can empty the pool while you wipe down the espresso machine, and then the nine o’clock recap has no allowance left. Write a ceiling into the first message, such as stop if this run would cost more than $2. If the screen has no meter, time is your meter. The National Institute of Standards and Technology (NIST) publishes an AI Risk Management Framework built on four verbs: govern, map, measure, and manage. Your three numbers are the “measure” step, and Stop is the “manage” step.
Watch the first loop
The earlier post on autonomy levels gave three modes: watch, approve, and walk away. Walking away is something you earn after one run that did what you wrote down. In our scene you walked away on the very first attempt at a site the agent had never seen. The partner page was a maze of marketing panels, a login teaser, and a “Download pack” button that served an error page with a .zip name. That is a first-loop job, so you stay.
Watching does not mean reading every word. Anthropic says the same in Cowork’s safety note: you will not check every command, so you look for unexpected patterns. Examples are scope creep, a site you never named, a file size that makes no sense, or a permission dialog that keeps coming back. You would have caught the 168 MB file on the second attempt if the file window had been visible next to the kettle. It was on the cutting board under a dish towel, because the steam made the screen bead.
So put the agent window where you can see its log, and open Finder (or File Explorer) on the destination folder, sorted by Date Added. The first surprise file is your alarm. If the name is vendor_skus (1).zip, the agent is already retrying into a new file, so stop it and do not wait for 23. Coding agents follow the same rule. A failed npm install that fills a folder with thousands of files is the same runaway zip with extra directories, and raising the iteration limit on a stuck command only buys a larger mess.
Find Stop before you start

The second figure shows four ways to stop a runaway agent. You want at least two of them ready before you press Start, because the first one can be slow. You click Stop, but if a download is already in progress, the bytes may still arrive. The caps you wrote fire even when you are not looking. Switching off the risky actions keeps the damage small, and closing the folder or denying the permission sheet works when the button lags.
Find Stop with your eyes before you type the goal. In Claude Cowork you halt the task from its task controls, and Anthropic’s safety page tells you to stop when the pattern looks wrong. ChatGPT’s agent mode and older “Operator” labels have moved more than once in 2026, and Gemini and Grok tuck the interrupt into different menus. Hover over the controls and confirm you can halt the run. If you cannot find an interrupt, stay in the chair.
One click is not always a hard stop. A shell job can run until its current step times out, and a browser download started by attempt 22 can finish after you hit Stop on attempt 23. That is why the folder window stays open. If your computer shows a low-disk warning, stop the agent, then quit the browser or turn off the folder permission so a 24th file never starts.
Imagine a coworker in purchasing messages you at that moment asking whether you got the catalog zip. You are tempted to type into the agent, “clean up the failed downloads and try again from the other URL.” That sentence is how a runaway becomes a delete loop. Closing the laptop lid is safer, since it pauses a local session, but a task scheduled in the vendor’s cloud would not pause.
Leave send and delete unarmed
Retries are annoying when they fill a disk, and they are expensive when they send mail, post to Slack, click Submit, or trash files. A loop that decides “the archive is corrupt, remove it and fetch again” will delete as it goes if deleting is allowed. A loop that decides “I should tell my coworker I am still working” will send 23 status emails if sending is allowed. A loop stuck on a permission dialog may keep pressing Allow. Cowork still asks before a permanent delete, according to Anthropic’s safety page. Other tools may not, so assume delete is on until you have seen the confirmation prompt yourself.
For this download job, a safe first setup is to let the agent browse the partner’s resources site and write one named path in Downloads, and nothing else. Renaming, shell commands, email, and form filling should all be off. If the product only offers one coarse “can use the browser” switch, stay and watch every click. Computer use, where the agent clicks the actual screen, is the coarsest switch of all, and Anthropic flags it as extra risk in Cowork because there is no protective sandbox between the model and what is on screen. A retrying clicker on a logged-in tab is how you end up buying 23 of something. You pressed Start, so the 23 zips or the 23 emails sit on your account, under OpenAI’s usage policies and Anthropic’s acceptable-use rules.
Worked example: 23 zips in 11 minutes
Same morning, same 18 MB catalog zip. The table below is a scoreboard you could have used, with the right stop for each kind of miss.
| Healthy retry | Runaway symptom | Kill action |
|---|---|---|
| One 503, wait, fetch the same URL once more | Same 403 or HTML-as-zip on the next try | Stop. Copy the URL into your own browser. Log in yourself. |
| File is 0 bytes; overwrite the same path after a new tactic | vendor_skus (1).zip appears; sizes climb (168 MB, 168 MB, 168 MB) | Stop. Quit the browser. Do not tell the agent to clean Downloads. |
| Login wall; agent pauses and asks you for 2FA | Agent reloads the login page or clicks Allow in a loop | Stop. Deny the permission sheet. Finish 2FA in a tab you own. |
| Six minutes, 5 actions, still no 18 MB file; agent reports the miss | 11 minutes, 23 actions, disk banner, quota half gone | Stop. Cap the next run at 8 actions and 6 minutes before Start. |
| You watch, then you send your coworker one line | Send or delete is on while the fetch retries | Disarm send and delete. You write the email. You trash the partials by hand. |
Paste this as the first message on the next vendor download. Edit the path and the three numbers, and leave the bans in place.
# Loop budget. Paste as message 1. Edit paths and numbers.
goal: Save ONE 18MB zip of public SKU CSVs
from vendor.example.com/resources
to ~/Downloads/vendor_skus_ok.zip
done_when: that file exists AND size is 15 to 25 MB
AND unzip -t succeeds
stop_if:
actions >= 8
minutes >= 6
spend_usd >= 2
same_error_count >= 2
extra_files_in_Downloads >= 1
permissions:
browse: vendor.example.com/resources only
write: ~/Downloads/vendor_skus_ok.zip only
delete: OFF
send: OFF
click_submit: OFF
shell: OFF
retry_policy: one different tactic after a failure, then ASK me
if_login_or_captcha: STOP and ping me
if_partial_file: leave it, do not rename, do not retry into (1).zip
overwrite: never create vendor_skus (n).zipThat block turns “go get the zip” into a budget with a kill switch. The model can still be wrong, but it cannot claim you asked it to keep pushing. If your vendor’s screen has toggles instead of a paste box, map each line onto a toggle before you walk to the kettle. If a toggle does not exist, you either lack that permission or you have it with no off switch, and in both cases you should stay in the chair.
Common mistakes
- Leaving for coffee on a first run. Walking away comes after a watched success.
- Treating a rising attempt count as grit. Twenty-three of the same 403 is a stuck plan.
- Letting the browser invent
(1).zip,(2).zip,(3).zipbecause you never said what to do about overwriting. - Asking the agent to “clean up the failed files” with delete still armed. You trash the partial files yourself.
- Starting a scheduled or cloud task that retries while the lid is closed.
- Skipping the Stop rehearsal. If you cannot point at the interrupt, you cannot leave the room.
- Turning on send, Submit, or computer-use clicks for a fetch that has never finished once.
How to practice this week
Pick a tiny public zip you already trust, such as a sample CSV pack you host or a vendor file you have on disk. Point the agent at a wrong address on purpose, using the budget block above while you watch. Confirm that it stops after two identical errors and that Downloads gains at most one junk file. Then point it at the real address with the same caps. The next post in this series covers checking agent work without being an engineer, where you open the zip and the spreadsheets like a skeptic. Today you only need the machine to halt. The rest of the path is on Learn. If you wanted files without a loop, that is still AI for files and office work, not an agent button.
Quick recap
- A retry is one new tactic. The same error twice is a stop.
- Cap steps, minutes, and spend in the first message if the screen has no setting for them.
- Watch the first loop. Walking away for coffee is earned, not assumed.
- Find Stop before Start. Keep the folder window open because in-flight downloads can still land.
- Keep send, delete, and Submit off until a watched run finishes clean. The 23 zips were the cheap version of this lesson.
Series notes
This is Part 4 of AI agents for everyone. Previous: Autonomy levels. Next: Checking agent work.
Sources
Vendor help pages checked in August 2026. Labels and limits move, so re-open the live page before you rely on a detail.
- Anthropic: Use Claude Cowork safely (watch patterns, stop if it looks off, scheduled tasks run while you are away, deletion still asks)
- Anthropic: Get started with Claude Cowork (stop, steer, and approval modes)
- Anthropic: Getting started with Claude
- OpenAI Help: ChatGPT agent (labels and limits move; confirm the interrupt and quota on your plan)
- OpenAI: ChatGPT for Mac and ChatGPT help
- Gemini app and Gemini Computer Use (consumer app vs developer loop: different tools)
- Grok (re-check current computer or bot controls; names move)
- OpenAI usage policies and Anthropic usage policy (actions the agent takes still sit on your account)
- NIST AI Risk Management Framework (map tools, measure the run, manage a stop)
- AMS: AI agents for everyone, the post on autonomy levels, and Learn
Keep going
Same lessons in your feed
Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.
