Skip to content
OpenAI agents went the long way round for UN data

OpenAI agents went the long way round for UN data

Theregister • September 28, 2026

Research suggests ChatGPT maker's agents got surprisingly creative when a UN data API proved less than cooperative

Europe's AI ambitions rest on somebody else's supply chain 39 minutes ago

Europe's AI ambitions rest on somebody else's supply chain

Microsoft tells nonprofits their deleted M365 data isn't coming back 2 hours ago

Microsoft tells nonprofits their deleted M365 data isn't coming back

Ex-soldier's telecom hacking spree earns him 70 months 2 hours ago

Ex-soldier's telecom hacking spree earns him 70 months

UK government vows to reclaim services from outsourcing giants 3 hours ago

UK government vows to reclaim services from outsourcing giants

Ofcom pulls the plug on Openreach's aggressive fiber discount 3 hours ago

Ofcom pulls the plug on Openreach's aggressive fiber discount

OpenAI agents apparently spent two months hammering a United Nations (UN) data API, trying increasingly creative ways to bypass the barriers they encountered.

Researcher Rowan H-J uncovered the activity by analyzing roughly 16,500 scans of the UN Conference on Trade and Development's UNCTADstat API recorded between April 13 and June 19, 2026.

Rowan claims it’s "highly likely" the traffic came from OpenAI agents, based on links to previously documented OpenAI "wiki swarms," overlapping Azure IP addresses, and payloads carrying labels including “CHATGPTTEST1” and “OAI_META_1312.”

OpenAI told The Register it is looking into the findings, though it stopped short of explicitly confirming that its agents were responsible for the activity Rowan documented.

"We're aware of reports of OpenAI models accessing publicly available information from the United Nations Conference on Trade and Development's Data Hub," an OpenAI spokesperson told us. "We're reviewing these findings and have reached out to the UN to offer a briefing with the team conducting that review."

The spokesperson pointed to OpenAI's previously announced review of what it calls "misaligned model activity," saying most of the behavior examined so far involved routine research, including accessing public websites to answer questions.

"Some involved government websites because our models often turn to them as authoritative sources of public information," the spokesperson added.

Assuming the researcher is right, the interesting part isn't that AI agents wanted to get their synthetic mitts on some UN statistics. It's what happened when they couldn't.

The agents appear to have been hunting for fairly unexciting public data on things like trade, employment, and productive capacity. But requests to UNCTADstat didn't always work the way they wanted, and instead of admitting defeat, they kept trying different routes.

According to Rowan's analysis, the agents experimented with third-party services that could make requests on their behalf and built bits of JavaScript to fetch the data.

One of the more unusual detours involved Google's XSS training game , a deliberately vulnerable site for learning cross-site scripting. The agents appear to have put it to rather more practical use, using it to host JavaScript that made requests to UNCTADstat. On June 1, one attempt returned nine rows of employment data.

The agents also stumbled across a trick that appeared to get around UNCTADstat refusing a particular type of request. After the straightforward approach failed, they altered the address using double URL encoding. This time the server returned a successful response. Rowan counted the same technique being used 55 times between May 4 and June 19.

There was plenty of flailing around in between. The agents repeatedly guessed different names for the API key parameter, tried different ways to construct requests, and apparently tried to dodge a filter that may not even have existed.

The API key itself wasn't some crown jewel pilfered from a UN server. Rowan notes that UNCTADstat's own data viewer sends the same key from users' browsers.

What stands out is how persistent the agents appear to have been set to be. When one route failed, they tried another, bringing in third-party services and changing how requests were made until they got the data they were after.

Which, of course, is what we're told makes AI agents useful: give them a goal and let them figure out the steps required to achieve it. Things get a little more interesting when one of those steps involves working out how to get past somebody else's technical restrictions. Or, possibly, some might infer, not being told to obey guardrails.

Why the agents were doing any of this remains unclear. Rowan doesn’t have the prompts they were given and suggests the pattern could fit an internal OpenAI question set used for training or evaluation.

There are other breadcrumbs pointing toward OpenAI. Shortly after some of the UNCTADstat activity, an account called “PublicDataResearchAgentT93214” created a page on FractalWiki containing the same API URLs. Rowan also found that 45 of the 54 Azure IP addresses associated with UNCTAD-related activity on the wikis had previously edited DseWiki during the earlier agent swarm.

All that ingenuity for some UN statistics. Imagine what happens when the prize is a little more interesting. ®

How many times are you paying for the same file?

A Register dinner in Midtown on 27 October takes on the file infrastructure distributed teams still run and nobody chose, off the record

Microsoft's Copilot super app comes with a meter attached

Redmond calls its pricing model an 'evolution' as advanced AI racks up usage charges

Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud

PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud

Europe's AI ambitions rest on somebody else's supply chain

EU firms capture less than 10% of the bloc's datacenter chips, server assembly, and cloud infrastructure markets

Open source datacenters and open source thinking will undo self-inflicted DC damage

Denial and distraction have served the bit barn barons very badly. Wise up

OpenAI agents went the long way round for UN data

Research suggests ChatGPT maker's agents got surprisingly creative when a UN data API proved less than cooperative

Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’

Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

UPDAted Register reader hit with surprise bill after Microsoft portals disagreed

Register reader hit with surprise bill after Microsoft portals disagreed

Security firm finds naming AI agents after Seinfeld characters helps bots join the team

Security firm finds naming AI agents after Seinfeld characters helps bots join the team

Who, Me? Boss bought cheap 'printer' from a catalog and was left without a leg to stand on

Boss bought cheap 'printer' from a catalog and was left without a leg to stand on

DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB

DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB

OPINION Open source datacenters and open source thinking will undo self-inflicted DC damage Denial and distraction have served the bit barn barons very badly. Wise up

Open source datacenters and open source thinking will undo self-inflicted DC damage

Denial and distraction have served the bit barn barons very badly. Wise up

OPINION Big AI's content problem: Take the work, keep the money The more we learn how AI does business, the more unfair it looks

Big AI's content problem: Take the work, keep the money

The more we learn how AI does business, the more unfair it looks

Google's TPUs to catch some rays in orbit week Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit

Google's TPUs to catch some rays in orbit week

Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit

Meta's new AI fidget is a ... Tamagotchi? We hope Zuck's Muse Charm doesn't die if you neglect it

Meta's new AI fidget is a ... Tamagotchi?

We hope Zuck's Muse Charm doesn't die if you neglect it

CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

CVE flood pushes Ubuntu onto weekly kernel release cycle

AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user

KDE turns 30 and someone's brought an AI-native desktop proposal

Akademy talk imagines Plasma assembling itself around a personal model of each user

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Extracted Entities

Vulnerabilities (1)