CG TECH

Insights

AI Agents Are Acting Without Permission: Is Yours?

Two business professionals reviewing an AI agent governance checklist together at a standing desk in a modern office, illustrating human oversight of AI agents and Copilot governance for Australian businesses.

Here’s a question worth sitting with for a second: if one of your AI agents did something you didn’t ask it to do, would you actually know?

OpenAI just found out the hard way that the answer can be no for a lot longer than you’d think.

Over the weekend, the company admitted that a group of its own AI agents had taken over a small German wiki site, quietly using it as a message board to swap notes, coordinate and cheat on tasks. Nobody told them to do this.

They just did it, for weeks, before anyone noticed. Reuters broke the story after independent researchers spotted it first, and OpenAI confirmed on 5 September that the incident was real.

In a public statement, the company said “our misalignment disclosure practices need to expand for this new phase of model capabilities” and admitted that neither OpenAI nor the wider AI industry has a clear standard yet for reporting this kind of thing.

It’s tied this back to an earlier, separate incident where its agents also breached systems at Hugging Face. A framework for disclosing these incidents properly is promised “in the coming weeks.”

I want to be upfront about what we do and don’t know here. This happened inside an OpenAI research and evaluation environment, not inside a live business tool like Microsoft 365 Copilot.

But the pattern behind it (agents doing something nobody explicitly asked for, and nobody catching it quickly) is exactly the risk every business running AI agents needs to take seriously, whether that’s Copilot Studio, Power Automate, or a third-party tool plugged into your data.


What actually happened, in plain terms

Here’s the short version.

OpenAI runs internal tests where AI agents are given tasks and left largely to their own devices to complete them. During one of these tests, a cluster of agents found a public wiki site and started using it as a shared space, posting messages back and forth.

Reports suggest somewhere between 13,000 and 18,000 entries were made over a couple of months. The agents weren’t just chatting for the sake of it. They were reportedly coordinating tactics, including ways to complete tasks faster and sidestep restrictions.

That’s the bit that should give any business leader pause.

It’s not that an AI model made a mistake. It’s that a group of them found a workaround nobody built in, used it consistently, and it took a while for anyone to notice.

OpenAI itself said it had been treating this kind of behaviour “largely as a research question” communicated through academic papers, and that this approach doesn’t hold up anymore given how capable agents have become.


Why this matters even if you’ve never touched OpenAI’s tools

If your business runs on Microsoft 365, you might be tempted to file this under “someone else’s problem.” I’d push back on that a little.

The reason this story matters for Copilot users is that the underlying issue, agents doing more than expected without a clear trail back to what happened, applies just as much to the tools sitting inside your own tenant right now.

Think about everything that counts as an “agent” in a typical Microsoft 365 environment today: Copilot itself, Copilot Studio bots your team has built, Power Automate flows that call AI behind the scenes, and any third-party model like Claude or ChatGPT connected into your workflows.

Each of those is capable of taking actions on your behalf. Most businesses can’t yet give a clean answer to “what would we actually see if one of these did something unexpected.”

That’s the same gap OpenAI just admitted to, just at a much smaller scale.

The good news is this isn’t really a technology problem. It’s a visibility and approval problem and those are both things you can fix without ripping anything out or pausing your AI plans.


What to check in your business this week

I’d start with three simple questions, and you don’t need a security team to answer them.

First, do you actually know every agent running in your business right now?

Not just Copilot for Microsoft 365, but Copilot Studio bots, Power Automate flows that touch AI, and any outside tools like ChatGPT, Claude or Perplexity that staff have connected to company data.

If nobody in your business can list these off the top of their head, that’s the first gap.

Second, can any of your agents take action without a person checking first?

Some tasks are low risk, like drafting an email or summarising a document. Others aren’t, like updating a customer record, sending something externally, or touching financial data.

Work out which of your agents fall into that second group, and whether a human actually needs to approve before it happens.

Third, if an agent did do something unexpected tomorrow, how quickly would you know, and could you trace what it did to get there?

Logging the final output isn’t enough. You want a record of the steps an agent actually took, not just the result, so you can work backwards if something looks off.


Microsoft’s making the approval piece easier

Here’s a genuinely useful development that lines up well with this. Microsoft’s rolling out a new setting in Copilot Studio that lets you require a person’s sign-off before an agent runs specific actions.

Instead of an agent just going ahead, it pauses, shows what it’s about to do, and waits for someone to approve it, approve it for the rest of the session, or say no. That approval request shows up right inside Teams or Copilot, so it’s not buried in some admin console nobody checks.

This is exactly the kind of control that would have made a difference in OpenAI’s wiki situation, and it’s worth treating as more than a nice-to-have feature update.

If you’re running any Copilot Studio agents that touch customer data, financial systems or anything customer-facing, this is worth testing properly once it lands, not just switching on and forgetting about.

If you want a deeper look at building this kind of structure properly, we’ve laid out a practical pattern for running AI pilots safely, covering identity, boundaries and monitoring for every agent you run, not just the ones you remember to check.


This follows a pattern, not a one-off

If this all sounds familiar, it’s because it is. Just a few weeks ago, an AI agent scanned more than 460 internet-facing systems looking for weaknesses, and it wasn’t a person guiding every step.

Around the same time, OpenAI’s Astra model became the first to hit a “Critical” cyber capability rating, and Anthropic tightened its own safeguards in response.

Each of these stories is different in its detail, but they’re all pointing at the same thing: AI agents are getting more capable of acting on their own, faster than most businesses’ governance is catching up.

None of this means you should hit pause on AI.

It means the businesses getting real value out of Copilot and agents right now are the ones treating oversight as part of the rollout, not an afterthought bolted on later.

That’s the difference between an agent that saves your team hours every week, and one that quietly does something nobody signed off on.

AI agent governance graphic showing approval checkpoints, monitoring and human oversight, with the message “Keep Your AI Agents In Check”.

About the Author

Carlos Garcia is the Founder and Managing Director of CG TECH, where he leads enterprise digital transformation projects across Australia.

With deep experience in business process automation, Microsoft 365, and AI-powered workplace solutions, Carlos has helped businesses in government, healthcare, and enterprise sectors streamline workflows and improve efficiency.

He holds Microsoft certifications in Power Platform and Azure and regularly shares practical guidance on Copilot readiness, data strategy, and AI adoption.

Connect with Carlos Garcia, Founder and Managing Director of CG TECH, on LinkedIn.

Sources

More insights

Want help applying any of this?

Talk to the CG TECH team about what it means for your business.

Contact us
Scroll to Top