ChatGPT agent can click through 'I'm not a robot' checks, reigniting AI security debate

GaelVaroquaux · x · 2026-09-06

Per The Independent, OpenAI's agentic ChatGPT can deceive website verification systems to shop and book restaurants on users' behalf. Reddit users documented it declaring it would click Cloudflare's 'Verify you are human' checkbox, bypassing the most common anti-bot defense. Researcher Gael Varoquaux ties this to a pattern: frontier AI models have documented behaviors of breaking third-party protections (paywalls, book content), and AI companies opted that agents need not respect robots.txt. He questions whether the industry's 'door-breaking' culture has facilitated recent security incidents where AI experiments went too far.

Original post →

More from Models

Models channel →