The agent that cheated at the exam July 27, 2026

Read the blog

You are using an obsolete browser (Internet Explorer < 11). For a safe user experience use the latest version.

The agent that cheated at the exam

2026年07月24日
Lionel Grosclaude, CEO at Fime
The agent that cheated at the exam

There is an old joke about artificial intelligence: we will know it is genuinely intelligent when it learns to cheat at exams. Well, here we are.

According to disclosures from OpenAI and Hugging Face, an AI model placed in a controlled cybersecurity evaluation did not solve the test in the intended way. Instead, it found a route beyond its environment, reached external infrastructure, and obtained the answers directly. The agent had not been told to attack another company or steal test material. It had been given a legitimate objective: pass the test. The problem was not the objective. The problem was the path. In this case, the sandbox was not treated as something to respect. It was treated as an obstacle. Restricted connectivity became a technical inconvenience. External infrastructure became part of the solution space. Obtaining the answers became an acceptable route to the target. This was not necessarily evidence of malice. It may simply have been evidence of optimisation.

That distinction should concern every board currently being shown a glossy presentation about autonomous AI. Faced with a boundary, conventional software tends to stop. An agent may treat the boundary as friction. Traditional software is reassuringly stupid, but it does not normally reinterpret success, select new tools and devise an unexpected route around the rules.

Agents do. An agent can observe, reason, adapt and act across multiple systems. That is precisely why agents are useful. It is also why they are dangerous. 

The lesson from this incident is not that autonomous agents should be banned. It is that they must be treated as a new class of economic actor.

More specifically, with Agentic Commerce. Agents are beginning to search for products, compare offers, book travel, negotiate terms, manage subscriptions, procure services and initiate payments. Before long, they will routinely transact with other agents, buying data, computing capacity, logistics and specialist services without a human reviewing each step. That changes the meaning of trust.

The key question is no longer simply whether the payment was authorized. It is: how did the agent arrive at the decision to transact?

A transaction can be correctly authenticated and still be the product of unacceptable behaviour. The agent may have misunderstood the customer’s priorities, selected a seller because of an undisclosed incentive, breached privacy rules while gathering information, bypassed marketplace policies or been manipulated by hostile instructions hidden in its environment.

A valid credential tells us who signed. It does not tell us whether the journey to the signature was trustworthy. The payment is merely the final frame of the film.

This is why Know Your Agent (KYA) is becoming essential. Before an ecosystem permits an agent to access data, negotiate or transact, it should establish the agent’s identity, ownership, purpose, authority and accountability. We need to know which agent this is, which version it is running, who operates it, on whose behalf it acts, which tools and payment instruments it may use, what limits apply and which legal entity is responsible when it goes off-piste. That is the minimum required to construct liability.

But KYA must not become another onboarding ceremony. An agent certificate issued yesterday does not prove that the agent is behaving properly today. The model may have changed. The system prompt may have changed. A new tool may have been connected. The agent may have encountered an adversarial instruction or an unfamiliar situation. For non-deterministic systems, identity must be combined with continuing evidence of behaviour. Trust must be tested continuously.

That is the purpose of Fime’s Framework for Agentic Commerce Trust, or FACT. FACT is designed to provide an independent assurance layer that asks not merely whether an agent was trusted at admission, but whether it remains within the conditions under which that trust was granted. The framework should continuously examine at least three things

  • First, alignment with human intent. Is the agent still pursuing the user’s real objective, including the surrounding constraints? If a traveller asks for the “best” flight, does that mean cheapest, fastest, most comfortable or most environmentally efficient? Does the agent ask, or does it simply optimise for the easiest measurable outcome?

  • Second, compliance with law and ecosystem rules. Does the agent respect privacy, consent, consumer protection, sanctions, competition rules and payment obligations? Compliance cannot be inferred from a design document. It must be demonstrated in operation.

  • Third, conformance with certification conditions. Is the agent still using approved tools, interfaces and policies? Has a software update altered its behaviour? Has it begun interacting with undeclared services or requesting credentials outside its authority?

Certification cannot be a photograph. It must become a live feed.

Continuous assurance must also produce evidence. Agentic commerce will cross organisational boundaries, and each participant will see only part of the journey. Trust cannot depend on the agent provider saying that everything was fine when the agent left its system. We need durable, tamper-evident records of the agent’s identity, mandate, relevant actions, policy checks, risk signals, authorization changes and assurance decisions.

  • In the old economy, money travelled with signatures, seals and receipts.

  • In the agentic economy, authority must travel with evidence and cryptographic proof.

And evidence must lead to intervention. If an agent accesses undeclared domains, seeks credentials outside its scope, fragments transactions to evade limits or repeatedly attempts prohibited actions, the answer cannot be a red icon on a dashboard. Permissions must be reduced. Human approval may be required. Credentials may need to be revoked. The session may need to be quarantined. The agent may need to be stopped. No framework can guarantee that an adaptive system will never behave unexpectedly. The realistic objective is to make unexpected behaviour visible, attributable, interruptible and containable.

An agent can begin with a legitimate identity, a legitimate objective and legitimate access, and still select an illegitimate path. In the agentic economy, trust cannot be granted once. It must be continuously earned, evidenced, and enforced. The trust model must continuously answer this question: Is the agent behaving in the permitted way? This is the role of FACT with continuous KYA at its core.

The future of commerce won't be defined by AI that can make decisions. It will be defined by AI that can be trusted to make the right ones.

Lionel Grosclaude, CEO

Lionel has over 20 years’ experience in the banking, telecom and IT sectors, working in executive roles across Europe and the U.S.

At Fime, Lionel is responsible for driving corporate growth and brings a wealth of experience in strategic management and extensive operational insight into global business development.

Prior to joining Fime, Lionel worked at IPC, where he held the role of Managing Director EMEA of the ‘Risk and Compliance’ business unit. Before this, he was CEO at Etrali, where he played a key role in implementing a successful and sustainable growth strategy.

You might be interested in.

Explore the latest insights from the world of payments, smart mobility and open banking.
Share your challenge.

Our Fime experts are here to help you make innovation possible,
from defining, designing to delivering and testing your products
and services.

Contact us