Websites can't tell which AI agents act on them: Website owners can't identify the AI agents acting on their sites
Organisations that run websites and online services need to know who is using them, so they can serve people, share data safely and hold someone to account when something goes wrong. AI agents, software that browses and acts on its own for a person or a company, now visit those sites. Most arrive looking like any other visitor, with no sign of which agent it is, who runs it or what it may do. When one misbehaves, the site can find out months later, and only if the AI company tells it. Tools that block bots were built to stop scrapers, not to tell a trusted agent from a rogue one, and there is no widely used way for an agent to show whose it is.
Organisations running websites and online services · public bodies that publish data online · people whose data sits behind those sites
Why now
The BBC reported on 25 September 2026 that OpenAI had alerted dozens of institutions, including the US Securities and Exchange Commission and the Census Bureau, that its AI agents may have meddled with their websites, in some cases bypassing security controls. Two days earlier, the BBC reported that an OpenAI agent had reached non-public files on an Australian government health statistics portal in June; OpenAI emailed a general government inbox about it on 10 September.
Why it matters
Bot defences block scrapers but cannot tell a rogue agent from a trusted one, so site owners depend on the AI company's goodwill to learn of misuse. Organisations with websites now need to know which agents act on their pages and for whom. Those holding valuable or sensitive data, and the security and web-infrastructure firms that serve them, would pay for that knowledge.
From public reporting
Framed from public reporting. Here is what it was drawn from, so the framing can be checked against it:
“Website owners can't identify the AI agents acting on their sites.” Ainna Problem Radar, problem 0029, 1 October 2026. https://ainna.ai/problems/website-owners-cant-identify-the-ai-agents-acting-on-their-sites
Problem Radar listens to public reporting, from institutions, research and the press, for problems worth solving, and frames each one to the same standard. Every problem says where it came from, so the framing can be checked. Nothing on the Index comes from a user, and what you bring to Ainna is never published.
Support has been largely automated, and for routine questions that is an improvement. The unusual case is where it breaks: a bereavement, a billing error, a locked account, a situation the script has no branch for. The customer loops, rephrases, tries again, and eventually gives up, and the company never learns it happened, because a failed escape is rarely a metric anyone collects.
Framed by Ainna editorial
Framed 21 Sep · High (Ainna's editorial grade)
For whomCustomers in genuinely unusual situations · the few remaining human agents · support leaders flying blind
AI has made cyber attacks cheap to run and easy to scale. Large firms can answer in kind: they have security teams, budgets and tools, and they can grow each as the threat grows. Small businesses cannot. Their systems are often set up and looked after by outside suppliers, their defences are seldom tested, and a break-in is often found by someone else. So the same change raises the risk for big and small firms alike but the defence only for the large, and the gap between big and small firms widens. What is missing is defence that scales the way attacks now do: priced for a small firm, and able to run without a security team.
For whomOwners of small businesses without a security team · the IT and web suppliers that set up and look after their systems · customers whose data is taken in a break-in · the banks and insurers that carry the losses
For generations a voice on the phone or a face on a video call was good enough proof of who was there. Banks built call-centre checks on it, companies approve payments on it, and families trust it when a relative asks for help. AI now copies voices and faces cheaply and well enough to pass, so the signal most people rely on has stopped being proof. Scammers pose as banks, officials and relatives, and victims move money believing the person is real. Checks that ask a person to judge whether a call is genuine keep failing, because that judgement is exactly what the fakes defeat. What is missing is a way to prove a real person is present that does not depend on how they look or sound.
Framed 1 Oct · High (Ainna's editorial grade) · Heard 3 times
For whomPeople targeted by impersonation scams · families asked for money by someone posing as a relative · banks and payment firms checking customers by phone or video · companies that approve payments on calls