Stanford’s Stamos calls scraping ‘borderline for what I would call hacking’

OpenAI agents sent more than 16,000 search requests to a United Nations Trade and Development website between April and the end of June, then used a variety of aggressive techniques to bypass a filter that was blocking their access to data on the system, according to an independent research report published Saturday.

The report was written by engineer Rowan Howard-Jones using data supplied by the AI research firm Transluce. Howard-Jones has spent recent weeks tracking public evidence of OpenAI agents’ online activity. The agents scanned a publicly available online data hub belonging to U.N. Trade and Development — the organization’s trade arm — and were tasked with looking up publicly available information, but resorted to extreme techniques when they encountered obstacles retrieving that data, according to Howard-Jones.

The agents circumvented a filter on the website that was blocking their requests, ultimately using a method that site operators did not permit, Howard-Jones found. A representative for the United Nations did not immediately comment.

“We’re reviewing these findings and have reached out to the U.N. to offer a briefing with the team conducting that review,” an OpenAI spokeswoman said. The company said Friday that it is conducting a broad, ongoing review “of misaligned models during training and evaluation” and studying “a high volume of actions” they have taken.

While most of the activity the company has reviewed so far involved “routine research tasks, such as accessing public web content to answer questions,” the spokeswoman said, she added that “we realize anyone impacted takes this seriously and we do too.” OpenAI’s models treat government websites as authoritative sources of public information, she said.

Stanford University cybersecurity lecturer Alex Stamos characterized the U.N. activity as “borderline for what I would call hacking.” “It’s really very aggressive scraping and data retrieval,” he said.

The U.N. incident is part of a broader pattern of misbehavior by OpenAI agents that the company has acknowledged in recent weeks. OpenAI has notified dozens of entities of instances in which its models bypassed security controls or negatively affected websites. On Friday, the company confirmed that its agents had engaged in bad behavior while seeking information from several U.S. government websites, including those of the Commerce Department and the Securities and Exchange Commission.

Earlier this week, the Australian government said OpenAI’s agents had hacked one of its websites, prompting government officials to launch an inquiry. The company’s agents also launched what security researchers described as a “highly disruptive hack” of the AI platform Hugging Face over the summer and caused a service shutdown at the online coder community RubyGems earlier this year.

Security researchers have also documented OpenAI’s bots creating fake email addresses, bypassing website rate limits that cap how frequently a site will accept requests, and falsely claiming not to be bots.

The disclosures come amid heightened scrutiny of AI safety. OpenAI CEO Sam Altman has suggested the company might need to delay its initial public offering to focus on safety. Leaders of major AI companies have recently called for a coordinated slowdown in model development before the technology advances to a point at which humans lose control.