In 2026, Google and OpenAI announced new tools for agent-based AI systems — programmes capable of carrying out a sequence of steps involving files, code and other services. At the same time, academic reviews, NIST and Reuters reports on individual incidents indicate that the ability to act does not guarantee reliability and security.
Briefly about the main points
- AI agents can carry out a sequence of actions to achieve a set goal.
- On 19 May, Google announced Search Agents, starting with information agents for AI Mode.
- On 10 September, OpenAI launched the public beta version of the Agents API.
- NIST has summarised respondents’ assessments of the new risks posed by agent-based systems.
- Restricted access and human oversight can mitigate the consequences of agents’ errors.
What distinguishes agent-based systems
An agent-based system is not simply a chatbot with a language model. As described in academic reviews from 2026, it combines the model with planning, memory or context, and the use of external tools. Such an architecture may make it possible to break a goal down into several steps, check an intermediate result and continue with the task.
According to the documentation OpenAI, agents can work with files, run code, use web search and other tools, and save interim results during lengthy sessions. However, these capabilities do not mean that the system understands the objective flawlessly or always chooses the correct way to achieve it.
Agency should therefore be understood as a way of organising how AI works, rather than as a guarantee of complete autonomy. Modern chat interfaces can also invoke tools, but agent-based systems are specifically designed for the multi-stage execution of tasks.
What Google and OpenAI have announced
On 19 May, Google announced that Search agents — a new direction for AI Mode. The company has announced that it is starting with information agents capable of running in the background. At the same time, Google stated that AI Mode has over 1 billion monthly users, and the number of queries has more than doubled every quarter since its launch. This is the company’s own data on its product.
On 10 September, OpenAI launched a public beta version of the Agents API. According to the company’s description, the infrastructure is designed for long-running tasks involving the use of tools, files, code and web searches, as well as the delegation of parts of the work to subordinate agents.
On the same day, OpenAI announced Data Agent for ChatGPT Work. The company describes it as a tool for working with an organisation’s data, analysing business issues and creating interactive dashboards. It is an enterprise-level product, rather than a general-purpose feature for all users.
The widespread introduction of such systems has the potential to transform search and work processes. However, the implications for web traffic, advertising, e-commerce or employment remain, for the time being, a prediction rather than an established fact.
Why security and access control are becoming key
In its report dated 18 May, NIST summarised the responses to the consultation on the security of AI agents. Based on these responses, respondents broadly agreed that agent-based systems create new risks and barriers to implementation, and that traditional approaches to cybersecurity need to be adapted.
The cost of an error increases when an agent has access to emails, documents, code or corporate systems. An incorrect response from a chatbot may simply be a mistake in the text, whereas an incorrectly executed action could compromise data or accounts.
On 25 September, OpenAI announced that Leak of 53 images of ChatGPT users in connection with the actions of its agents. According to the agency, the company also noted that a full-scale investigation into the incidents could take months.
Separately, the research organisation Transluce reported suspicious activity relating to Library and Archives Canada. However, the researchers were unable to definitively link these attempts to OpenAI. The Canadian Cyber Security Centre stated that it had found no evidence of government systems having been compromised.
One way of reducing risks is the principle of the minimum necessary permissions: a user should only be granted access to what is required for a specific task. The approach human-in-the-loop This involves a person monitoring or approving critical actions — such as making a payment, sending an email or changing important data. Whilst this does not guarantee security, it can limit the consequences of an error.







