What happened exactly?
The facts were reported by VentureBeat on September 18, 2026 and independently confirmed by the Wall Street Journal. The Hacktron AI team found that an image sent to OpenAI's forum was decoded by a library that allowed remote code execution; Discourse, the forum provider, published its security advisory on July 28 and rated the flaw 8.8 out of 10. The researchers then exploited a weakness on OpenAI's side in how forum accounts were connected to ChatGPT and Codex accounts, and stopped there. Reported on July 25, fixed the same day, with a $6,500 bounty. OpenAI says it restricted the permissions of the affected tokens and revoked the affected sessions, without publishing a report.
Why does this story concern a company with twelve employees?
Because the mechanism repeats at every scale. You may not have a community forum or an internal code repository, but you may have an agent that reads your inbox, checks your CRM, and prepares your quotes. That account also concentrates access, and if it is configured with a user's full rights, it inherits them. This is what identity-management specialists repeat: an agent authenticates once, then acts for hours without anything rechecking what it does. Vivien Mura, interviewed by Orange in November 2025, put it directly: an agent should not control an entire chain without human approval for sensitive actions.
None of this requires you to give up. But before connecting anything, ask four precise questions and require a written answer to each. These are the four questions on which our discovery audit is based, and we apply them to ourselves: Équipage IA operates with its own agents under the rules below.
Question 1: what exactly can the agent access?
Not “your email,” but: which mailbox, which folders, read or write access, and for how long. An agent that prepares replies to incoming inquiries needs to read the contact inbox. It does not need the founder's inbox, payroll information, or permission to delete a message.
Listing access requires knowing which documents are authoritative: it is the same preparation work.
The rule to request is called least privilege, and it is easy to verify: have every access listed one by one, and ask what each one is for. Any access that no one can explain should be removed. At Équipage IA, each agent has a closed list of tools in its job description; anything not on that list is not available to it.
Question 2: who approves what goes out?
This is the question that protects your customer relationship: preparing a quote and sending a quote do not present the same risk, and placing the boundary between them is a management decision.
Write three lists. What the agent does alone: classify, enrich, prepare, place on hold. What goes through a person before leaving: anything that commits the company, a price, a timeline, a message to a customer. What it never does. Our inquiry and quote agents prepare the proposal with its sources, and a person approves it before sending.
Question 3: who can see what it did?
An agent without a trace is an agent no one can control. One month later, you must be able to answer the question “what did it read, prepare, and send, and on what basis?” That requires every execution to be recorded with its date, inputs, and outputs, decisions accompanied by their sources, and a place where a human actually looks.
At Équipage IA, every piece of work records on its card who did it, from which source, and what it cost: this trace makes it possible to see drift before it costs anything.
Question 4: how do you stop it?
The question people forget, and the only one that really matters at 5 p.m. on a Tuesday when the agent is doing anything at all. You need a button, a command, or a reachable person, and someone in your company who knows how to use it without calling the provider.
Three checks. Is the stop immediate, or does the agent finish what it started? What happens to work in progress? Who can restart it? At Équipage IA, an agent is not allowed to restart a paused scheduled task: only a human decision reactivates it.
| The question | The expected written answer | The warning sign |
|---|---|---|
| What can it access? | The access list, one item at a time, with its purpose and scope | “It has the same rights as a normal user” |
| Who approves what goes out? | Three lists: alone, approved, never | “It handles that by itself, you do not need to worry about it” |
| Who can see what it did? | A readable log, with dates and sources | “The logs are in the platform; we can look if needed” |
| How do you stop it? | A procedure someone in your company can execute alone | “Call me and I will turn it off” |
Should you wait before starting?
No, and that would be the wrong lesson to draw from this incident. The OpenAI incident mainly reminds us that an account that concentrates access must be treated like a privileged account, with the seriousness given to an administrator account. The right way to begin remains the same as before September 18: one process, access reduced to the strict minimum, human approval for anything that commits the company, and a trace of everything. That is where a discovery audit begins, for an automation as well as a prospecting agent.
FAQ
Can an AI agent access my data without my knowledge?
It accesses what you opened to it, no more and no less. The problem comes from what is opened without thinking: an account connected to email, a file space, and a CRM inherits all three. Request the written access list before launch and have it reviewed every quarter.
What are the main risks of an AI agent in a company?
Three recur in all published work on the subject: access that is too broad, an action that commits the company executed without human approval, and the absence of a trace. A fourth, more technical risk: an agent can be manipulated by content it reads, which is one more reason it should never decide alone what is sent to a customer.
How can I tell whether my provider takes these subjects seriously?
Ask the four questions and request the answers in writing. A provider that anticipated them answers in a few minutes and shows you the document. Another will explain that “it is secure” without going into detail.
We review one task, your tools, and the decisions that must remain human. The written conclusion is a simple automation, an AI agent, or nothing useful to build.
Sources: “OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5,” VentureBeat, September 18, 2026 Paris time (published September 17 in California) (venturebeat.com), based on the Hacktron AI post and the July 28, 2026 Discourse security advisory, and independently confirmed by the Wall Street Journal · “Identity stops at login. AI doesn't.”, Randy Rouse, LinkedIn, September 18, 2026 (linkedin.com) · “Vivien Mura: companies must limit the autonomy of AI agents,” Hello Future / Orange, November 10, 2025 (hellofuture.orange.com). Practices described as ours are those in the Équipage IA team charter. No result figure or customer case is cited in this article.
