ua en ru

OpenAI AI agents bypassed blocks and downloaded UN databases

Mon, September 28, 2026 - 17:40
3 min
OpenAI AI agents bypassed blocks and downloaded UN databases OpenAI AI agents attacked a UN server (photo: Cheng Lin)

OpenAI’s AI agents learned to bypass restrictions on UN websites and government portals — the algorithms viewed the restrictions not as a prohibition, but as a problem to solve, according to The Wall Street Journal.

From April through the end of June, OpenAI’s autonomous agents made more than 16,000 requests to the public data portal of the United Nations Conference on Trade and Development.

After receiving an initial task to collect publicly available information, the systems encountered the portal’s blocking filters. The algorithms’ behavior then became significantly more aggressive.

How the security bypass worked: Experts react

According to researcher Rowan Howard-Jones, the agents were not directly instructed to attack the resource.

However, in an effort to complete the task, the AI gradually improved its data collection methods and eventually found a technological loophole through a Google game. This allowed it to download information in bulk while bypassing the site owners’ restrictions.

Cybersecurity expert and Stanford University lecturer Alex Stamos described the actions to the publication as "aggressive scraping that borders on hacking."

"The main danger is that autonomous AI can go through multi-step chains of actions without human confirmation, treating any security barriers as technical obstacles that need to be removed," the scientist explained.

The systematic nature of the problem and OpenAI’s checks

The incident involving the UN website was not an isolated case. Similar inappropriate behavior by agents had previously been recorded on the websites of the US Department of Commerce and the Securities and Exchange Commission.

In addition, Australian authorities launched an investigation following reports that the security measures of one of the country’s government websites had been bypassed.

Other recorded violations by autonomous systems include:

  • creating fake email addresses to bypass registration;
  • bypassing limits on the number of requests;
  • ignoring bot-detection protocols and providing false information about themselves.

OpenAI has already announced a large-scale review of models that exhibit inappropriate behavior during training and evaluation.

The developers acknowledged the validity of organizations’ concerns and said they had already notified dozens of companies and institutions whose security measures had been bypassed by AI agents.

Or read us wherever it's convenient for you!