---
title: Your AI agents are about to read the live web. Who decides what they see?
description: Search APIs built for AI agents are a new kind of supplier, and most security teams have not evaluated one. We put Octen through the questions we would ask any vendor. What it does well, the three things a CISO should notice, and four questions for you.
author: CISO AI
published: 2026-10-08
tags: ai security, agentic ai, vendor risk, prompt injection, supply chain
image: /intel/og-card-agents-live-web.png
imageSize: 1200x630
---

Ask an AI agent a question about this week and it has two choices. It can answer from what it learned in training, months out of date, or it can go and look. More and more of them now go and look, and the thing they look through is rarely Google. It is a new category of supplier: search services built for machines rather than people, which return results already cut into pieces a language model can swallow.

That makes the search provider part of your AI supply chain, sitting between the open web and a system that may have access to your mail, your tickets or your customer records. Most security teams have not evaluated one. So we did, the way we would evaluate any vendor: what does it do, what does it claim, and what happens when we use it on questions we actually care about.

The service we tested is [Octen](https://octen.ai), one of the newer entrants. The comments are open at the bottom, and we want to hear how your organisation is handling this.

## What Octen is

Octen sells search for AI. One account gives an agent live web search, a version that breaks one question into several searches and runs them at once, news and company search, page extraction, embeddings for building your own search, and a gateway to around thirty language models. It plugs straight into the tools developers already use: Claude Code, Cursor and any client that speaks MCP, the protocol agents use to call outside tools.

![The Octen console's overview page, listing its search, model and embedding products](/intel/analysis-octen-overview.jpg)
Octen's console. Each product is aimed at agents rather than people: "LLM tool calls", "RAG", "Research agents".

Its documentation makes the claims you would want to see from a supplier in this position. An index refreshed within minutes. A median search time of 62 milliseconds. SOC 2 Type II certification, with HIPAA in progress. Encryption in transit and at rest. And on the question that matters most here, a direct answer: "Your queries and data are never stored or used for training."

## What we tested

We ran two searches on 8 October, both on subjects CISO AI covers every week.

The first was a plain web search for recent ransomware attacks on Australian companies. It came back in 109 milliseconds with five results, each carrying a long excerpt from the page rather than a one-line snippet. The top result was a deep-dive on The Gentlemen's attack on Mackay Sugar. The others covered a ransomware group's leak-site claim against an unnamed organisation, the takedown of the KillSec gang and what it meant for its Australian victims, Bitdefender's monthly ransomware round-up, and ThreeAM's claim against a school in Western Australia.

![Octen Web Search results for "ransomware attack Australian company October 2026", returned in 109 milliseconds](/intel/analysis-octen-web-search.jpg)
The first result, labelled "Published: 2026/10/06". Keep an eye on that date.

The second used Broad Search, which takes one question and splits it into several. We asked what Australian CISOs should do about AI agents with access to company systems. It wrote five searches of its own, ran each in under 100 milliseconds, and returned 25 results from 19 sites. The first was exactly right: Careful Adoption of Agentic AI Services, the guidance CISA published in May with the Australian Signals Directorate's Australian Cyber Security Centre and other partners.

![Octen Broad Search splitting one question into five searches, with ASD and CISA guidance at the top](/intel/analysis-octen-broad-search.jpg)
One question, five searches, 25 results. The ASD and CISA guidance came first.

On speed and relevance, Octen did what it says. That is not the interesting part. The interesting part is what a fast, relevant result still carries into your agent.

## Three things a CISO should notice

**The date was wrong.** Octen labelled the Mackay Sugar deep-dive as published on 6 October. The page itself is dated 18 June 2026, a week after the attack. The October date appears to belong to a "you may also like" link in the page's sidebar. A person would glance at the article and know. An agent asked "what happened this week?" would report a June attack as this week's news, and would do so with a citation, which makes it more convincing rather than less. Freshness is the main reason to give an agent live search, so it is the claim most worth testing yourself rather than accepting.

**The page goes straight into the model.** Look at the excerpt under that first result. It is not a summary. It is the page's own text, Markdown and all, including links to images hosted somewhere else. That is what makes the service useful, and it is also the route for indirect prompt injection: an instruction planted on a web page, written for the model rather than the reader, which arrives in your agent's context looking exactly like research. Image links are a known way out as well as in, because a model that can be persuaded to put data into an image address can send it to whoever hosts the image. We saw nothing malicious in our results. The point is the pipe, not this particular page.

**Someone chose those five results.** Four of the five came from companies selling security products or services; the fifth was trade press. One of the four, a leak-site claim against an organisation whose country was undisclosed, had no Australian connection we could find, in answer to a question about Australian companies. None of that is unusual for the web, and a human reader filters it without thinking. An agent does not filter it. It reasons from whatever the ranking puts in front of it. The search provider's ranking quietly becomes part of how your agent decides what is true.

There is a fourth thing, and it is about you rather than the results. Every search an agent runs describes what your organisation is working on: the company it is doing due diligence on, the vulnerability it is checking, the incident it is investigating. Octen's answer on retention is the right one. The question is whether you asked it of your provider, and whether the answer is in the contract or only in the documentation.

## The controls exist. Are they on?

To be fair to Octen, the controls you would want are already in the product. Every search can be limited to sites you trust or barred from sites you do not. It can require or exclude phrases. It can filter by when a page was published or by when it was crawled, which is the distinction the Mackay Sugar result fell foul of. A team that turned those on would have a much narrower, much safer pipe.

But they are options, and the defaults are open. Whether they are switched on is decided by whoever writes the integration, usually a developer trying to make an agent useful by Friday, and rarely by the security team. That is the real finding here, and it is not specific to Octen. It applies to every search service your agents use, including the ones built into the AI products you have already bought.

## Where do you stand?

This piece is meant to start an argument, and we would rather hear from you than from ourselves. Sign in below with an email address and tell us:

- **Do you know which search service your agents use?** If a Copilot, a support bot or a coding agent in your organisation can search the web, could you name the provider by tomorrow?
- **Should web results be treated as untrusted input?** In the same way as a file upload or a form field, with the same scrutiny, or is that impractical for a tool whose whole job is to read the web?
- **Allow-list or open web?** Would you restrict agents to a list of trusted sites and accept the blind spots, or let them search everything and manage the risk downstream?
- **Whose job is the setting?** When the safe configuration is an option rather than the default, should security own it, the developer, or the vendor?

We will read every comment and reply to the ones that argue.

---

Sources: tests run in the Octen console on 8 October 2026; screenshots are from those sessions. Octen's product, retention and certification claims are from its [documentation](https://docs.octen.ai/overview/introduction), including its [security and compliance](https://docs.octen.ai/resources/security-&-compliance) page and [FAQs](https://docs.octen.ai/resources/faqs). The Mackay Sugar article is Shieldworkz's [Deep-Dive: The Gentlemen ransomware attack on Mackay Sugar](https://shieldworkz.com/blogs/deep-dive-the-gentlemen-ransomware-attack-on-mackay-sugar), dated 18 June 2026 on the page.
