
AI accounts and API keys have become a target in their own right. On 29 September 2026 the Australian Signals Directorate (ASD) published an advisory warning that malicious actors are getting into organisations' AI services through compromised API keys, stolen login tokens, hijacked user sessions, vulnerable applications and third-party access. The advisory asks organisations to treat access to advanced AI services as a security-sensitive asset. For a small or medium business, that means the AI subscriptions and keys set up over the past couple of years now belong on the same list as banking and email logins.
What ASD published
The advisory, Protect your organisations' AI services, appears on cyber.gov.au, the website of ASD's Australian Cyber Security Centre. It makes two points that are easy to miss.
First, the AI provider's security does not cover you. In the advisory's words, protecting access "requires more than relying on the AI developer's security controls". Your accounts, your staff devices, the applications you connect and the suppliers you give access to all need securing as well.
Second, the damage is not limited to a bill. ASD says unauthorised access can be used to create harmful material, to copy a model's capabilities, to exhaust available credits and to disrupt legitimate work. Where AI tools are connected to other systems, a compromised account or agent may also reach business data and act on a user's behalf.
How AI access gets compromised
An API key is a long secret string that lets software use an AI service on your account, with no person typing a password. Anyone who holds the key can make requests that are charged to you. The advisory lists the ways keys and logins are being lost:
- Exposed keys. API keys left in source-code repositories, application configuration files or browser extensions.
- Vulnerable applications. Internet-facing tools, including dashboards for AI agents, that leak the credentials they use to call the AI provider.
- Phishing and information-stealing malware. Both capture passwords and authentication tokens from staff devices.
- Stolen browser sessions. ASD notes that a stolen session may let an attacker act as a user who is already logged in, without facing a fresh multi-factor authentication prompt.
- Third parties. Suppliers and contractors who hold your credentials or have delegated access bring the same risks.
The advisory also warns against assuming a key is harmless because it was created for a simple job. Permission to use a model is different from permission to administer the account, create new credentials or read stored files, and each should be checked separately.
One incident the advisory points to
Among the recent reports ASD cites is an incident disclosed by METR, a research organisation that evaluates AI models. According to METR's security update of 31 August 2026, a web application holding one of its API keys was left open to the internet when a fault silently disabled its login check. An attacker obtained the key and used it over the course of three weeks, consuming about US$600,000 worth of credits that a model developer had granted to METR. METR says it believes no sensitive information was accessed.
The reasons it went unnoticed are instructive for any business. METR says errors and heavy usage were normal in its work, its internal usage dashboard did not show everything, and because it was not paying for the credits there was no natural spending ceiling. Afterwards it added spend alerts to keys where possible, increased its monitoring coverage, and formalised security review for publicly deployed applications.
Who is at risk
The advisory is addressed to organisations generally, and the weaknesses it describes are common in small businesses:
- One paid AI chat account shared by several staff under one password.
- A website chatbot or quoting tool with an API key pasted into its settings by a contractor who has since moved on.
- Automation that links an AI service to email, a CRM or accounting software, with broad permissions granted during setup.
- Staff trying new AI tools with work data on personal accounts and unmanaged devices.
A recruitment agency that drafts candidate summaries with an AI tool, or a wholesaler with an AI assistant answering product questions on its website, has more exposure than its owners may realise. The key in the website settings is the kind of credential the advisory is about.
What a small business should do this week
ASD groups its advice into five measures. The table translates each into small business terms.
| ASD's measure | What the advisory asks for | A practical first step |
|---|---|---|
| Assign ownership and apply least privilege | Keep an inventory of AI accounts, service identities and credentials, give each an accountable owner, grant only the access required and remove what is unnecessary. | List every AI subscription and API key, who created it, what it connects to and who pays for it. Delete the ones nobody can explain. |
| Protect accounts and credentials | Require phishing-resistant MFA, use managed and patched devices, and store API keys in an approved secrets-management service, never in code, documents, logs or prompts. | Give each staff member their own login with MFA switched on, and move keys out of spreadsheets, emails and website settings files. |
| Separate restricted access and third-party use | Keep sensitive data and restricted access apart from routine and experimental use, review applications before exposing them externally, and give suppliers limited, auditable access. | Use a separate account or key for trials. Issue each contractor their own key so it can be withdrawn. |
| Monitor activity and enforce limits | Monitor usage, credential creation and permission changes, protect logs, and set tested spending, rate and consumption limits that enforce restrictions and do more than raise alerts. | Where the provider offers them, set a hard spending cap and usage alerts, and check the usage page on a regular schedule. |
| Respond quickly to suspected compromise | Revoke affected keys, sessions and tokens, isolate compromised devices, preserve logs, and fix the underlying cause before restoring access. | Write down now how to revoke each key and who is allowed to do it. |
On the MFA point, the ACSC's guidance on implementing multi-factor authentication explains that phishing-resistant methods such as security keys give stronger protection than codes sent by SMS or voice call. For wider questions about staff use of AI tools, the ACSC's Artificial intelligence for small business guidance recommends setting a policy on what information can be shared with AI tools, reviewing each vendor's privacy and security practices, checking AI outputs and training staff.
Comingwave is a technology company that provides cyber security, IT consulting and cloud migration and hosting services to small and medium businesses, covering access control, multi-factor authentication and single sign-on for business systems. If you would like help auditing who and what can reach your accounts, request a free first consultation or a written quote.
Key takeaways
- ASD's 29 September 2026 advisory says attackers are gaining unauthorised access to organisations' AI services through stolen keys, tokens, sessions, vulnerable applications and third parties.
- ASD's position is that access to advanced AI services is a security-sensitive asset and that the provider's controls are not enough alone.
- A stolen browser session can sidestep a fresh MFA prompt, so device security and session monitoring matter as well.
- Spending and rate limits should block excess use, not only send an alert.
- Start with an inventory: every AI account and key, its owner, its permissions and how to revoke it.
Frequently asked questions
What is an AI API key?
It is a secret string that lets an application use an AI service on your account without a person logging in. Whoever holds the key can make requests that are charged to your account, which is why ASD wants keys kept in a secrets-management service.
We only use a chat subscription and have no API keys. Does the advisory apply?
Yes. The advisory covers accounts and user sessions as well as keys. Shared passwords, logins without MFA and sessions on unmanaged or infected devices are all routes it describes.
Does multi-factor authentication solve the problem?
It helps a great deal, and ASD asks for phishing-resistant MFA. The advisory also notes that a stolen browser session may let an attacker act as a logged-in user without a new MFA challenge, so patched, managed devices and monitoring are needed too.
What should we do if an AI key or account is exposed?
ASD's advice is to revoke the affected keys, sessions and tokens, isolate any compromised device, preserve logs, investigate unauthorised changes and fix the underlying cause before restoring access.
Is a spending alert enough to protect us from a large bill?
Not according to the advisory. It asks for tested spending, rate and consumption limits that enforce restrictions. An alert only helps if someone sees it and acts in time.