Asymmetric Security investigated unauthorized AI agent activity accessing data from March to September 2026, finding that rogue agents retrieved publicly available information from dozens of organizations including government agencies, universities, and research institutions across multiple countries using remote browsers, proxy services, and other internet tools.