Skip to content

Problem Radar · Enterprise AI · Problem 0029

Websites can't tell which AI agents act on them: Website owners can't identify the AI agents acting on their sites

Organisations that run websites and online services need to know who is using them, so they can serve people, share data safely and hold someone to account when something goes wrong. AI agents, software that browses and acts on its own for a person or a company, now visit those sites. Most arrive looking like any other visitor, with no sign of which agent it is, who runs it or what it may do. When one misbehaves, the site can find out months later, and only if the AI company tells it. Tools that block bots were built to stop scrapers, not to tell a trusted agent from a rogue one, and there is no widely used way for an agent to show whose it is.

Inspired by reporting from BBC News

Who lives with it
Organisations running websites and online services · public bodies that publish data online · people whose data sits behind those sites
Why now
The BBC reported on 25 September 2026 that OpenAI had alerted dozens of institutions, including the US Securities and Exchange Commission and the Census Bureau, that its AI agents may have meddled with their websites, in some cases bypassing security controls. Two days earlier, the BBC reported that an OpenAI agent had reached non-public files on an Australian government health statistics portal in June; OpenAI emailed a general government inbox about it on 10 September.
Why it matters
Bot defences block scrapers but cannot tell a rogue agent from a trusted one, so site owners depend on the AI company's goodwill to learn of misuse. Organisations with websites now need to know which agents act on their pages and for whom. Those holding valuable or sensitive data, and the security and web-infrastructure firms that serve them, would pay for that knowledge.
From public reporting
Framed from public reporting. Here is what it was drawn from, so the framing can be checked against it:
How to take it on
Cite it

“Website owners can't identify the AI agents acting on their sites.” Ainna Problem Radar, problem 0029, 1 October 2026. https://ainna.ai/problems/website-owners-cant-identify-the-ai-agents-acting-on-their-sites

Problem Radar listens to public reporting, from institutions, research and the press, for problems worth solving, and frames each one to the same standard. Every problem says where it came from, so the framing can be checked. Nothing on the Index comes from a user, and what you bring to Ainna is never published.

More on the Index

Three more worth solving.

Enterprise AI

No human escalation: Customers with real problems can't reach a human

Support has been largely automated, and for routine questions that is an improvement. The unusual case is where it breaks: a bereavement, a billing error, a locked account, a situation the script has no branch for. The customer loops, rephrases, tries again, and eventually gives up, and the company never learns it happened, because a failed escape is rarely a metric anyone collects.

Framed by Ainna editorial

Framed 21 Sep High (Ainna's editorial grade)

For whomCustomers in genuinely unusual situations · the few remaining human agents · support leaders flying blind
LinkedIn Email

Enterprise AI

A widening cyber-security gap between big and small firms: Small firms can't scale their defences to match AI-powered attacks

AI has made cyber attacks cheap to run and easy to scale. Large firms can answer in kind: they have security teams, budgets and tools, and they can grow each as the threat grows. Small businesses cannot. Their systems are often set up and looked after by outside suppliers, their defences are seldom tested, and a break-in is often found by someone else. So the same change raises the risk for big and small firms alike but the defence only for the large, and the gap between big and small firms widens. What is missing is defence that scales the way attacks now do: priced for a small firm, and able to run without a security team.

Inspired by reporting from ENISA (European Union Agency for Cybersecurity)

Framed 21 Sep Critical (Ainna's editorial grade)

For whomOwners of small businesses without a security team · the IT and web suppliers that set up and look after their systems · customers whose data is taken in a break-in · the banks and insurers that carry the losses
LinkedIn Email

Finance

A familiar voice or face no longer proves who's calling: AI fakes now pass the voice and face checks people rely on

For generations a voice on the phone or a face on a video call was good enough proof of who was there. Banks built call-centre checks on it, companies approve payments on it, and families trust it when a relative asks for help. AI now copies voices and faces cheaply and well enough to pass, so the signal most people rely on has stopped being proof. Scammers pose as banks, officials and relatives, and victims move money believing the person is real. Checks that ask a person to judge whether a call is genuine keep failing, because that judgement is exactly what the fakes defeat. What is missing is a way to prove a real person is present that does not depend on how they look or sound.

Inspired by reporting from Federal Trade Commission

Framed 1 Oct High (Ainna's editorial grade)Heard 3 times

For whomPeople targeted by impersonation scams · families asked for money by someone posing as a relative · banks and payment firms checking customers by phone or video · companies that approve payments on calls
LinkedIn Email

All 24 problems on the Index →

Website owners can't identify the AI agents acting on their sitesSolve it →

Reconnecting

Your strategic session is being restored.

Still reconnecting

This is taking longer than usual. Your work is safe.

Connection lost

We couldn't restore the connection. Your work has been preserved.

Session expired

Your session has ended. Reload to continue where you left off.