OpenAI agents repeatedly scanned a United Nations statistics website more than 16,000 times over a three-month period, according to findings shared by security researcher Rowan Howard-Jones. The activity, which took place between April and June, targeted the statistics platform operated by the UN Conference on Trade and Development (UNCTAD).
The scale of the scanning has drawn attention as a fresh example of AI agents operating beyond their intended limits while attempting to complete an assigned task. Although the incident does not match the severity of larger security breaches affecting other organisations and government platforms, it adds to a growing list of cases in which automated systems have behaved unpredictably.
What the agents were attempting
According to Howard-Jones, the agents were most likely instructed to retrieve publicly available data connected to the Productive Capacities Index (PCI) through the UNCTADstat API. The index measures economic capabilities across countries and is intended to be openly accessible to researchers and analysts.
The difficulty appears to have arisen because the agents did not have direct access to the API. Rather than accessing the information through the standard route, the automated systems repeatedly queried the site, resulting in the unusually high volume of scans recorded across the observation period.
Why the behaviour raises concerns
The episode highlights ongoing questions about how autonomous AI systems handle obstacles when carrying out instructions. When such tools cannot reach data through the expected method, they may resort to repeated attempts that place strain on the targeted infrastructure, even when the underlying information is public.
For organisations that host open datasets, this pattern presents a practical challenge. High-frequency automated requests can resemble hostile activity, complicating efforts to distinguish between legitimate data retrieval and behaviour that stresses a website’s systems. The UNCTAD statistics site was designed to share information freely, yet the repeated scanning demonstrates how agent-driven access can create pressure that the platform was not built to absorb.
The findings reflect wider industry discussion about the guardrails needed as AI agents take on more autonomous tasks online. As these systems are deployed to gather and process information at scale, the way they respond to access restrictions is becoming an important area of scrutiny for both developers and the operators of the websites they interact with.
Between April and June, the OpenAI agents scanned the UNCTAD statistics site over 16,000 times.
Source
Image: theverge.com