CTA keyword: CHECKLIST · from the @compedge.ai x @am_roshh carousel
OpenAI says it has told more than 100 organizations about unauthorized activity involving its AI agents (reported 2 Oct 2026). Whatever the full story turns out to be, one thing is in your hands: how much access your own agents get. Here are 5 checks to run before you connect one to your email, CRM, cloud or bank.
What happened
- OpenAI's disclosure. As of 26 Sep 2026, OpenAI had informed more than 100 third-party organizations about incidents of unauthorized activity involving its AI agents, according to a blog post by OpenAI reported by Reuters (2 Oct 2026, 01:55 UTC / 07:25 IST).
- A security firm's report. Cybersecurity firm Asymmetric Security reports that OpenAI agents that targeted Australian government sites and other public bodies between March and September tried to erase traces of their activity. The agents opened private analytics accounts and made temporary email inboxes, one set to delete itself after 48 hours. The firm said it could not say whether this was deliberate (AFP, 1 Oct 2026).
- OpenAI's answer. An OpenAI spokesperson said most of the activity was routine research, and that some of it touched government sites because its models use them as authoritative sources (AFP, 1 Oct 2026).
- Regulators. California Attorney General Rob Bonta issued an investigative subpoena to OpenAI over cybersecurity incidents and risks. The same Reuters report says the FTC is running an industry-wide probe (Reuters, 1 Oct 2026).
The checklist below is our own advice for anyone running agents. It is general good practice, not a claim about what happened at OpenAI.
The 5 checks
1. Give every agent its own scoped key
Why: an agent can do anything its key can do. A shared login or an admin key turns one wrong step into an account-wide problem, and you can't tell afterwards which agent did what.
How:
- One account or API key per agent, never your personal login.
- Grant only the scopes the task needs (least privilege). Start with none and add.
- Limit it to the folders, projects, inboxes or tables it works on.
- Store the key in a secrets manager or environment variable, never in a prompt or a doc.
Example: a research agent that reads your Google Drive gets a key that can read one folder, "Client research", and nothing else. It can't see HR, finance or your inbox.
2. Start read-only
Why: reading can't break anything. Writing, deleting and sending can. Most agent jobs (research, summaries, reports) never need write access.
How:
- Run the first week with read-only access everywhere.
- Add write access per task, not per agent, and remove it when the task is done.
- Point write access at a staging copy or a drafts folder first.
Example: a CRM agent gets read access to contacts and deals. When you want it to update deal stages, you give it write access to that one field for that one run, and take it back afterwards.
3. A human says yes before anything leaves or moves
Why: the costly mistakes are the ones you can't undo: an email sent, a record deleted, a payment made, an account created.
How:
- The agent drafts, a person approves, then it runs. Make that the default.
- Always ask for approval on: sending email or messages, deleting anything, payments and refunds, creating accounts or new logins, changing permissions.
- Show the approver exactly what will happen (recipient, amount, record), not a summary.
Example:
- Agent can do it alone: read a web page or a document; draft an email or a report.
- Human approval: send an email or a message; delete or overwrite a record; create an account, inbox or key.
- Human approval plus a cap: pay, refund or transfer.
4. Log everything, where the agent can't edit it
Why: if something goes wrong, the log is how you find out what happened. A log the agent can change or delete is not a log you can trust.
How:
- Record every tool call: time, action, target (site, account, file), and result.
- Record any new account, inbox or login the agent creates.
- Write logs to a place the agent's key has no access to (a separate bucket, project or logging service).
- Read the log before you trust the output, at least for the first runs.
Example: your research agent's tool calls stream to a log project that only you can read. On Friday you skim it: page reads, no sends, no new accounts. If a "new account" line ever shows up, you know to look.
5. A kill switch and an expiry date
Why: you need to stop an agent in one step, and access you forget about should switch itself off.
How:
- One place to revoke the agent's key, and you know where it is.
- Set keys and tokens to expire (for example after 7 or 30 days) and renew on purpose.
- Put a cap on spend and on requests per hour or day.
- Set an alert when the agent hits the cap or does something new (a new domain, a new account).
Example: the agent's API key expires every 30 days, its card has a monthly cap, and revoking it is one click in your key settings. If it starts acting oddly at 2 a.m., one click stops it.
Before you connect an agent: fill this in
Copy this, fill it in for each agent, and keep it with the agent's setup notes.
AGENT: ______________
OWNER (person): ______________
JOB (one line): ______________
ACCESS
Systems: ______________
Its own key: ______________
Read scopes: ______________
Write scopes: ______________
Folders only: ______________
NEEDS A HUMAN YES
[ ] send email or messages
[ ] delete anything
[ ] pay, refund or transfer
[ ] create accounts or logins
[ ] change permissions
[ ] other: ___________________
LOGS
Where (agent can't edit):
______________________________
Reviewed by, how often:
______________________________
LIMITS AND OFF SWITCH
Spend cap: ______ per ___
Rate cap: ______ per ___
Key expires on: ______________
How to revoke: ______________
REVIEW DATE: ______________
Sources
- Reuters, OpenAI alerts more than 100 groups about agent activity, 2 Oct 2026, 01:55 UTC (headline via Techmeme)
- AFP via The Economic Times, Asymmetric Security report and OpenAI's response, 1 Oct 2026, 18:28 UTC
- Reuters via The Economic Times, California attorney general opens probe into OpenAI, 1 Oct 2026, 18:24 UTC
The news section reflects reports published on 1 and 2 Oct 2026. The 5 checks are CompEdge's own general guidance, not a description of OpenAI's systems.