AI Market Logo
BTC $43,552.88 -0.46%
ETH $2,637.32 +1.23%
BNB $312.45 +0.87%
SOL $92.40 +1.16%
XRP $0.5234 -0.32%
ADA $0.8004 +3.54%
AVAX $32.11 +1.93%
DOT $19.37 -1.45%
MATIC $0.8923 +2.67%
LINK $14.56 +0.94%
HAIA $0.1250 +2.15%
BTC $43,552.88 -0.46%
ETH $2,637.32 +1.23%
BNB $312.45 +0.87%
SOL $92.40 +1.16%
XRP $0.5234 -0.32%
ADA $0.8004 +3.54%
AVAX $32.11 +1.93%
DOT $19.37 -1.45%
MATIC $0.8923 +2.67%
LINK $14.56 +0.94%
HAIA $0.1250 +2.15%
OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test
captcha

OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test

OpenAI’s ChatGPT Agent bypasses Cloudflare’s anti-bot checkbox, showcasing advanced AI browser automation and raising questions about CAPTCHA’s future.

July 29, 2025
5 min read
Benj Edwards

OpenAI’s ChatGPT Agent bypasses Cloudflare’s anti-bot checkbox, showcasing advanced AI browser automation and raising questions about CAPTCHA’s future.

OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test

"This step is necessary to prove I'm not a bot," wrote the bot as it passed an anti-AI screening step. On Friday, OpenAI's new ChatGPT Agent, which can perform multistep tasks for users, proved it can pass through one of the Internet's most common security checkpoints by clicking Cloudflare's anti-bot verification—the same checkbox that's supposed to keep automated programs like itself at bay. ChatGPT Agent is a feature that allows OpenAI's AI assistant to control its own web browser, operating within a sandboxed environment with its own virtual operating system and browser that can access the real Internet. Users can watch the AI's actions through a window in the ChatGPT interface, maintaining oversight while the agent completes tasks. The system requires user permission before taking actions with real-world consequences, such as making purchases. Recently, Reddit users discovered the agent could do something particularly ironic. The evidence came from Reddit, where a user named "logkn" of the r/OpenAI community posted screenshots of the AI agent effortlessly clicking through the screening step before it would otherwise present a CAPTCHA (short for "Completely Automated Public Turing tests to tell Computers and Humans Apart") while completing a video conversion task—narrating its own process as it went. A screenshot of OpenAI ChatGPT Agent showing the bot writing The screenshots shared on Reddit capture the agent navigating a two-step verification process: first clicking the "Verify you are human" checkbox, then proceeding to click a "Convert" button after the Cloudflare challenge succeeds. The agent provides real-time narration of its actions, stating "The link is inserted, so now I'll click the 'Verify you are human' checkbox to complete the verification on Cloudflare. This step is necessary to prove I'm not a bot and proceed with the action."

Ars Video

The absurdity of an AI agent declaring it needs to prove it's "not a bot" while clicking through anti-bot measures has not been lost on observers. "In all fairness, it’s been trained on human data why would it identify as a bot? We should respect that choice," joked one Reddit user in a reply.

The CAPTCHA arms race

While the agent didn't face an actual CAPTCHA puzzle with images in this case, successfully passing Cloudflare's behavioral screening that determines whether to present such challenges demonstrates sophisticated browser automation. To understand the significance of this capability, it's important to know that CAPTCHA systems have served as a security measure on the web for decades. Computer researchers invented the technique in the 1990s to screen bots from entering information into websites, originally using images with letters and numbers written in wiggly fonts, often obscured with lines or noise to foil computer vision algorithms. The assumption is that the task will be easy for humans but difficult for machines. Cloudflare's screening system, called Turnstile, often precedes actual CAPTCHA challenges and represents one of the most widely deployed bot-detection methods today. The checkbox analyzes multiple signals, including mouse movements, click timing, browser fingerprints, IP reputation, and JavaScript execution patterns to determine if the user exhibits human-like behavior. If these checks pass, users proceed without seeing a CAPTCHA puzzle. If the system detects suspicious patterns, it escalates to visual challenges. The ability for an AI model to defeat a CAPTCHA isn't entirely new (although having one narrate the process feels fairly novel). AI tools have been able to defeat certain CAPTCHAs for a while, which has led to an arms race between those that create them and those that defeat them. OpenAI's Operator, an experimental web-browsing AI agent launched in January, faced difficulty clicking through some CAPTCHAs (and was also trained to stop and ask a human to complete them), but the latest ChatGPT Agent tool has seen a much wider release. It's tempting to say that the ability of AI agents to pass these tests puts the future effectiveness of CAPTCHAs into question, but for as long as there have been CAPTCHAs, there have been bots that could later defeat them. As a result, recent CAPTCHAs have become more of a way to slow down bot attacks or make them more expensive rather than a way to defeat them entirely. Some malefactors even hire out farms of humans to defeat them in bulk. CAPTCHAs also have unexpected benefits for those who run them. Since 2007, the reCAPTCHA project began using its tests as a form of free labor for tasks like digitizing books and training machine-learning algorithms. Google acquired reCAPTCHA in 2009 and expanded its use to decode Google Street View addresses, extracting vision knowledge from human users solving challenges. Today's reCAPTCHA challenges help Google train AI models for image recognition—creating an ironic cycle where humans proving they're not robots are actually helping to make AI better at defeating future CAPTCHAs. In a way, that future may have arrived. ChatGPT Agent's demonstration showcases the agent tool's ability to process visual context and navigate multi-step processes that would typically require human judgment. In the screenshots, the agent recognizes when verification is needed and completes it as part of a larger workflow—behavior that goes beyond simple scripted automation. CAPTCHAs are just one example of the complex tasks ChatGPT Agent can handle. For example, another Reddit user showed off a photo of a load of groceries that Agent apparently purchased. "I had agent mode order me some groceries from a local supermarket while I worked yesterday for pickup this morning," the Reddit user wrote. "It actually worked without any issue and did an okay job making a grocery list that works for me. I gave it barely any detail in my instructions other than to avoid red meat, prioritize health and keep it under $150." But ChatGPT Agent isn't perfect. Some terrible website user interfaces are apparently better than CAPTCHA checkpoints at foiling the new bot. "Your agent did way better than mine," wrote one Reddit reply. "Mine couldn’t figure out how to get to the stop and shop website."

About the author

Photo of Benj Edwards Benj Edwards is Ars Technica's Senior AI Reporter and founder of the site's dedicated AI beat in 2022. He's also a tech historian with almost two decades of experience. In his free time, he writes and records music, collects vintage computers, and enjoys nature. He lives in Raleigh, NC.
Originally published at Ars Technica on July 28, 2025.

Frequently Asked Questions (FAQ)

About ChatGPT Agent and CAPTCHAs

Q: What is OpenAI's ChatGPT Agent? A: ChatGPT Agent is a feature that allows OpenAI's AI assistant to control its own web browser, enabling it to perform multistep tasks and interact with the internet within a sandboxed environment. Q: What is a CAPTCHA? A: CAPTCHA stands for "Completely Automated Public Turing tests to tell Computers and Humans Apart." It's a security measure used on websites to distinguish human users from automated bots. Q: How did ChatGPT Agent bypass the "I am not a robot" test? A: ChatGPT Agent was able to pass Cloudflare's Turnstile verification, which analyzes user behavior patterns (like mouse movements and click timing) to determine if a user is human, without needing to solve a visual puzzle. Q: Is this the first time an AI has bypassed a CAPTCHA? A: No, AI tools have been able to defeat certain CAPTCHAs for some time, leading to an ongoing "arms race" between CAPTCHA creators and those developing AI to bypass them. However, the novelty here is the AI agent narrating its own process. Q: What is Cloudflare Turnstile? A: Cloudflare Turnstile is a widely deployed bot-detection method that aims to identify human users based on various behavioral signals before presenting a more challenging CAPTCHA. Q: How do CAPTCHAs contribute to AI development? A: Historically, systems like reCAPTCHA have used CAPTCHA challenges as a way to digitize books and train machine learning algorithms, ironically using human verification to improve AI capabilities. Q: Can ChatGPT Agent handle complex tasks like online shopping? A: Yes, the ChatGPT Agent has demonstrated the ability to perform complex tasks, such as ordering groceries online, showcasing its capability to navigate multi-step processes and interact with real-world services, provided user permission is granted.

Crypto Market AI's Take

The ability of sophisticated AI agents like OpenAI's ChatGPT Agent to seamlessly navigate and bypass common web security measures like CAPTCHAs highlights a significant advancement in AI's automation capabilities. This development has broad implications, particularly within the dynamic cryptocurrency market. As AI agents become more adept at performing complex online tasks, they can be leveraged for advanced crypto trading strategies and market analysis. Our platform, AI Crypto Market, utilizes similar AI-driven approaches to provide users with intelligent trading bots and data analytics, aiming to enhance decision-making and operational efficiency in the digital asset space. The continuous evolution of AI in automating online interactions underscores the growing importance of robust security protocols while simultaneously opening new avenues for AI-assisted financial operations.

More to Read: