AI service security is becoming an important concern for organisations as attackers find ways to access AI services through stolen credentials, compromised accounts and vulnerable applications. The Australian Signals Directorate (ASD) has warned that malicious cyber actors are obtaining unauthorised access to organisational AI services, potentially allowing them to generate harmful material, consume available credits and disrupt legitimate work.
The warning highlights how AI API keys, stolen authentication tokens, compromised user sessions and third-party access arrangements can expose AI services to misuse. Organisations must secure their own accounts, devices, applications and credentials rather than relying solely on the security measures provided by AI developers.
One route to unauthorised AI access involves exposed API keys. These credentials may be stored in source-code repositories, application configuration files or browser extensions, where attackers can obtain them. Vulnerable agent dashboards and other internet-facing applications can also expose credentials used to connect to model providers.
An attacker who obtains a valid key may be able to send requests directly to an AI service without using the organisation’s legitimate application.
Phishing, information-stealing malware and compromised third-party services present additional risks. A stolen browser session can allow an attacker to act as an authenticated user without completing a new multi-factor authentication challenge. Suppliers and contractors can also introduce exposure when they hold organisational credentials or delegated access.
The impact depends on the compromised identity’s permissions. Access to use a model does not necessarily grant permission to administer an account, create credentials or retrieve stored files. Organisations need to assess these privileges separately instead of assuming every credential has appropriately restricted access.
The risks can extend beyond direct access to an AI model. Compromised accounts, sessions or AI agents may be able to interact with connected enterprise systems, invoke tools, access organisational data or communicate with other agents on a user’s behalf.
Consequently, the practical impact of a compromised identity may reach connected systems and sensitive information, depending on the access available to that identity or agent.
Organisations should separate restricted-model access and sensitive data from routine AI use and experimental environments. Applications exposed externally should undergo security reviews, while suppliers should receive limited, auditable access.
Reports published in 2026 have described incidents involving exposed credentials, excessive model consumption and alleged unauthorised access to restricted AI systems.
On September 9, The Hacker News reported research from Okta that identified still-valid AI API keys and unexpired authentication tokens in data stolen from infected computers.
On September 1, The Register reported an incident in which an attacker spent three weeks consuming public-model credits worth approximately US$600,000. METR’s disclosure described an authentication flaw in an internet-facing agent dashboard that enabled the theft of a model-provider API key.
Separately, Reuters, citing Bloomberg, reported on April 21 that unauthorised users had accessed Claude Mythos Preview, which was restricted to selected organisations. The reporting concerned alleged access through a vendor environment, not confirmation of a compromise of the model developer’s core infrastructure.
ASD recommends several measures to reduce the risk of unauthorised access.
Organisations should maintain an inventory of AI accounts, service identities and credentials, assign an accountable owner to each, and apply least privilege by granting only the access required for each role. Unnecessary permissions should be removed promptly.
Account protection should include phishing-resistant MFA, managed and patched devices, monitoring for suspicious session activity, and approved secrets-management services for API keys. Credentials should not be exposed in code, documents, logs or prompts.
Security teams should also monitor model access, credential creation, permission changes and unusual consumption patterns. Audit logs must be protected against tampering, while tested spending, rate and consumption limits should enforce restrictions rather than merely generate alerts.
If compromise is suspected, organisations should revoke affected API keys, sessions and tokens, isolate compromised devices, preserve logs and investigate unauthorised changes. Access should be restored only after the underlying cause has been addressed.
These measures can help organisations reduce exposure while maintaining controlled access to AI services.