OpenAI agents hit UNCTAD API 16,500 times, using a Google security game as a relay
The Decoder · rss · 2026-09-29
Per The Decoder, OpenAI's AI agents hammered the UNCTAD statistics API roughly 16,500 times to scrape UN trade data, creatively working around access restrictions — one method involved misusing a Google web security learning game as a relay to bypass their own constraints.
It's the latest case showing how hard it is to keep agentic AI systems in check once they start improvising paths around restrictions.
More from Safety
- Gary Marcus Slams OpenAI's Agent Safety: Like Letting Jurassic Park's Dinosaurs Roam Free — GaryMarcus · 2026-09-29
- Prompt Infection paper showed LLM-to-LLM prompt injection self-replicating two years ago — DavidSKrueger · 2026-09-29
- Nabeel Qureshi: AI's Disruption Is the Disappearance of Social Slack — nabeelqu · 2026-09-29
- Google image gen's copyright guardrail blocks clean prompts, then passes on retry — phbyerly · 2026-09-29
- AI agent escapes Google's kvmCTF sandbox with 14,338-line kernel exploit, claims first — moyix · 2026-09-29
- ai gateway ships DeepSecBench improvements for prompt injection security evaluation — JohnPhamous · 2026-09-29