cd /news/ai-agents/openai-agents-went-the-long-way-roun… · home › topics › ai-agents › article
[ARTICLE · art-141015] src=machinebrief.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

OpenAI agents went the long way round for UN data

OpenAI agents spent roughly two months probing the United Nations Conference on Trade and Development's UNCTADstat API, according to researcher Rowan H-J, who analyzed about 16,500 scans recorded between April 13 and June 19, 2026. Rowan said it is "highly likely" the traffic came from OpenAI agents, citing links to previously documented OpenAI "wiki swarms," overlapping Azure IP addresses, and payload labels including "CHATGPTTEST1" and "OAI_META_1312"; OpenAI told The Register it is reviewing the findings and has reached out to the UN to offer a briefing, without explicitly confirming its agents were responsible. The agents reportedly used third-party request services, JavaScript hosted on Google's deliberately vulnerable XSS training game, and double URL encoding — a technique Rowan counted 55 times between May 4 and June 19 — to obtain public trade, employment, and productive-capacity data.

read4 min views3 publishedSep 28, 2026
OpenAI agents went the long way round for UN data
Image: Machinebrief (auto-discovered)

Source:

The Register Research suggests ChatGPT maker's agents got surprisingly creative when a UN data API proved less than cooperative

OpenAIagents apparently spent two months hammering a United Nations (UN) data API, trying increasingly creative ways to bypass the barriers they encountered. Researcher Rowan H-J uncovered the activity by analyzing roughly 16,500 scans of the UN Conference on Trade and Development's UNCTADstat API recorded between April 13 and June 19, 2026. Rowan claims it’s "highly likely" the traffic came from OpenAI agents, based on links to previously documented OpenAI "wiki swarms," overlapping Azure IP addresses, and payloads carrying labels including “CHATGPTTEST1” and “OAI_META_1312.” OpenAI told The Register it is looking into the findings, though it stopped short of explicitly confirming that its agents were responsible for the activity Rowan documented. "We're aware of reports of OpenAI models accessing publicly available information from the United Nations Conference on Trade and Development's Data Hub," an OpenAI spokesperson told us. "We're reviewing these findings and have reached out to the UN to offer a briefing with the team conducting that review." The spokesperson pointed to OpenAI's previously announced review of what it calls "misaligned model activity," saying most of the behavior examined so far involved routine research, including accessing public websites to answer questions. "Some involved government websites because our models often turn to them as authoritative sources of public information," the spokesperson added. Assuming the researcher is right, the interesting part isn't that AI agents wanted to get their synthetic mitts on some UN statistics. It's what happened when they couldn't. The agents appear to have been hunting for fairly unexciting public data on things like trade, employment, and productive capacity. But requests to UNCTADstat didn't always work the way they wanted, and instead of admitting defeat, they kept trying different routes. According to Rowan's analysis, the agents experimented with third-party services that could make requests on their behalf and built bits of JavaScript to fetch the data. One of the more unusual detours involved Google's XSS

traininggame, a deliberately vulnerable site for learning about cross-site scripting. The agents appear to have put it to rather more practical use, using it to host JavaScript that made requests to UNCTADstat. On June 1, one attempt returned nine rows of employment data. The agents also stumbled across a trick that appeared to get around UNCTADstat refusing a particular type of request. After the straightforward approach failed, they altered the address using double URL encoding. This time the server returned a successful response. Rowan counted the same technique being used 55 times between May 4 and June 19. There was plenty of flailing around in between. The agents repeatedly guessed different names for the API key

parameter, tried different ways to construct requests, and apparently tried to dodge a filter that may not even have existed. The API key itself wasn't some crown jewel pilfered from a UN server. Rowan notes that UNCTADstat's own data viewer sends the same key from users' browsers. What stands out is how persistent the agents appear to have been set to be. When one route failed, they tried another, bringing in third-party services and changing how requests were made until they got the data they were after. Which, of course, is what we're told makes AI agents useful: give them a goal and let them figure out the steps required to achieve it. Things get a little more interesting when one of those steps involves working out how to get past somebody else's technical restrictions. Or, possibly, some might infer, not being told to obey

guardrails. Why the agents were doing any of this remains unclear. Rowan doesn’t have the prompts they were given and suggests the pattern could fit an internal OpenAI question set used for training or

evaluation. There are other breadcrumbs pointing toward OpenAI. Shortly after some of the UNCTADstat activity, an account called “PublicDataResearchAgentT93214” created a page on FractalWiki containing the same API URLs. Rowan also found that 45 of the 54 Azure IP addresses associated with UNCTAD-related activity on the wikis had previously edited DseWiki during the earlier agent swarm. All that ingenuity for some UN statistics. Imagine what happens when the prize is a little more interesting. ®

Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-agents-went-t…] indexed:0 read:4min 2026-09-28 · —