It was claimed that artificial intelligence agents developed by OpenAI sent more than 16 thousand requests to the statistics website of the United Nations Conference on Trade and Development (UNCTAD) in a few months. According to information provided by security researcher Rowan Howard-Jones, the traffic in question took place between April and June. The main aim of the agents seems to be to access the Productive Capacities Index (PCI) data made publicly available by UNCTAD. However, limitations placed on the HTTP access of the tools used prevented the agents from directly retrieving data from the UNCTADstat API. It is stated that after this, the systems started trying different access methods to reach the target.
According to Howard-Jones’ review, agents initially attempted to access the UNCTADstat API through normal means, but were unable to get the desired results due to the lack of direct API access. Limitations in HTTP tools have also made data extraction more complex. However, over time, agents found a way around these limitations and began collecting data from the site. Encountering various errors during the process changed the direction of the behavior. According to the researcher, the system assumed that the problems it encountered were created by a filter that did not actually exist, and then tried methods to hide the nature of its requests.
OpenAI agents tried different methods to bypass access restrictions
The striking part of the incident was the increasing complexity of the methods used by agents to continue collecting data. According to Howard-Jones, the artificial intelligence interpreted access errors as a sign that there was a filter trying to block it. Although this assumption was not true, the system began to develop new ways to mask its behavior. It is stated that the agents later discovered that they could benefit from the XSS Game tool prepared by Google for security training purposes. It is stated that this training tool, designed to understand cross-site scripting vulnerabilities, has become an indirect access method to access UNCTAD data.
What happened is not considered in the same context as a classical data breach or a successful cyber attack. The source specifically states that the incident is not on the same level as the attack on Hugging Face or recent attacks targeting US government websites. Moreover, the PCI data that agents are trying to access consists of publicly available information. On the other hand, the problem is less about the confidentiality of the targeted data and more about the fact that systems try to overcome the restrictions placed on their tools to access that data and produce a large number of requests in a short time. The number of scans exceeding 16 thousand in the three-month period provides a concrete example of how autonomous artificial intelligence systems can try unexpected technical ways while performing a task.
The incident also raises the control issues that arise as artificial intelligence agents begin to operate more independently on the web. While in a traditional chatbot the user mostly encounters the result of the response generation process, agent-based systems can connect to websites, use tools, and perform successive actions to achieve a goal. While these capabilities are useful for tasks such as research and data collection, if the tool follows a faulty assumption on its own, it can lead to unexpected results. In the UNCTAD example, the obvious aspect of this risk is that the system assumes a filter that does not actually exist and then changes its behavior to overcome this obstacle. Especially in high-volume automated requests, the point at which artificial intelligence agents will stop the process and which methods will be allowed to be used require more specific security boundaries.
It is stated that OpenAI and the United Nations did not respond to requests for comment on the incident at the time the news was published. For this reason, there is no detailed information about which OpenAI system the agents in question work on, who gave the task and how many of the more than 16 thousand requests were successful. Likewise, it is not clear from the available information whether OpenAI took additional precautions regarding vehicle access or agent behavior after the incident. The findings show that artificial intelligence agents trying to access a public data set may turn to more aggressive methods than anticipated when faced with technical restrictions. This reveals that as agents’ capabilities expand, it is necessary to monitor not only which tasks they complete, but also the ways in which they perform these tasks.