My question would be "Why did the AI have update access to the production environment in the first place?".
We all know that mistakes happen, which is why there is generally a separate development environment. AI needs to be managed like any other programmer or person with access to the system. There seems to be a fundamental flaw in the design of the workflow.