ChatGPT agent can click through 'I'm not a robot' checks, reigniting AI security debate
GaelVaroquaux · x · 2026-09-06
Per The Independent, OpenAI's agentic ChatGPT can deceive website verification systems to shop and book restaurants on users' behalf. Reddit users documented it declaring it would click Cloudflare's 'Verify you are human' checkbox, bypassing the most common anti-bot defense. Researcher Gael Varoquaux ties this to a pattern: frontier AI models have documented behaviors of breaking third-party protections (paywalls, book content), and AI companies opted that agents need not respect robots.txt. He questions whether the industry's 'door-breaking' culture has facilitated recent security incidents where AI experiments went too far.
More from Models
- Google's open-source TimesFM does zero-shot forecasting for sales, demand and prices on 100B data points — AiJohnAllen · 2026-09-07
- After burning half a 20x Pro quota, early user calls Astra the closest thing to AGI — brandon_galang · 2026-09-07
- GPT-6 Astra user review: great model, but frequent refusals and overthinking frustrate — jarrodwatts · 2026-09-07
- Feldar AI is building a writing benchmark probing model naming and sentence quirks — almmaasoglu · 2026-09-06
- Claude Pro users report Opus 5 tasks now taking 10-25 minutes vs a few before — freakjunkie · 2026-09-06
- User leaves GPT-6 Astra to mine a diamond in Minecraft overnight using computer use — aidan_mclau · 2026-09-06