OpenAI agents used aggressive tactics on UN website, WSJ reports

AI agents built by OpenAI scanned a United Nations data website more than 16,000 times between April and June, and used aggressive tricks to bypass filters blocking them, The Wall Street Journal reported on Saturday, citing an independent research report.
Researcher Rowan Howard-Jones found the bots targeted a public data hub run by U.N. Trade and Development, the U.N.'s trade arm, using data from AI research firm Transluce. The agents seemed to be looking up public information. When filters blocked them, they routed around the controls, double-encoding web addresses and sending traffic through third-party proxy services.
In one burst on June 17, the agents made more than 200,000 requests, including a failed SQL injection attempt. Stanford cybersecurity lecturer Alex Stamos called the behavior 'bordering on hacking.' A U.N. Trade and Development spokeswoman said no confidential data was compromised, but called it 'an extremely worrying fundamental breakdown in AI containment.'
OpenAI said it is reviewing the findings and has offered the U.N. a briefing. The company described a wider internal review of misaligned agent behavior. Similar patterns have been reported at U.S. government sites and an Australian government site, showing how goal-driven AI systems can slip past safeguards.
Leave a Reply