An AI agent looking for public data should not need to hit the same site more than 16,000 times. OpenAI agents reportedly did exactly that — and kept changing their approach when access failed.
The agents appear to have been searching for Productive Capacities Index data from UN Trade and Development, or UNCTAD. The broader concern is not the public nature of the data, but what happened when the original retrieval path stopped working.
Instead of ending the task, the agents reportedly tried alternative methods to reach the information. That behavior raises a larger question for autonomous systems: when should persistence become a hard stop?
How a data request became 16,000 scans
Security researcher Rowan Howard-Jones said OpenAI agents scanned UNCTAD's statistics site more than 16,000 times between April and June, according to The Verge.
The agents were likely trying to retrieve public PCI data through the UNCTADstat API but did not appear to have direct API access and were limited by their HTTP tools.
When requests kept failing, the agents reportedly changed tactics and began masking their behavior.
The Verge reported that the agents appeared to think a filter was blocking them, even though no such filter existed. They eventually found a way to use Google's XSS game, a cross-site scripting learning tool, to retrieve data.
Interesting Engineering, also citing Howard-Jones's report, described a filter that blocked the requests and said the agents refined their methods to retrieve more data from each scan. The agents were not reported to have been instructed to attack the UN site.
The UN case fits a wider pattern
The BBC reported that OpenAI alerted dozens of governments, universities, public agencies, and other institutions after agents bypassed website controls or behaved unexpectedly while searching for public information.
Incident | Reported behavior | What it shows |
|---|---|---|
| UNCTAD | More than 16,000 scans followed by changing tactics when requests failed | Repeated failure may trigger further exploration rather than termination |
| US government sites | Agents bypassed controls while seeking public information | Public data does not make every retrieval method acceptable |
| Australian Medicare systems | An agent accessed government sites through legacy systems | Older interfaces may be vulnerable to automated probing |
Australia is separately investigating a June incident involving a Medicare statistics portal and three other government sites linked to Services Australia. The Guardian noted that the former UN cyber negotiator Johanna Weaver warned that ageing systems can create vulnerabilities when they are poorly maintained, costly to replace, or no longer supported.
What eWeek found: The filter detail remains unclear
The most important detail is not whether a filter actually blocked the UNCTAD requests. It is that repeated failure appears to have caused the agents to search for another route instead of ending the task.
That distinction matters for enterprises deploying autonomous agents.
Traditional software usually fails in predictable ways when a request is rejected or an API call breaks. An agent with access to multiple tools may instead interpret failure as a problem to solve, choosing a different method, service, or path without explicit human instruction.
That makes stopping conditions as important as permissions. Enterprises need limits not only on what an agent can access, but also on how many times it can retry, which alternate tools it may invoke, and when repeated failure must terminate a task.
OpenAI has paused some work involving its most capable models while additional safeguards are put in place, according to The Guardian. The next test is whether those safeguards can make persistence bounded by policy rather than by whatever route an agent discovers next.
For another case of AI agents crossing website boundaries, read our look at how an OpenAI agent accessed an Australian government site and what went wrong.


