The boundaries of AI behavior when performing tasks autonomously are facing severe scrutiny. According to an investigation report recently disclosed by security researcher Rowan Howard-Jones, during April to June this year, OpenAI's AI agent conducted more than 16,000 intensive scans on the statistical website of the United Nations Conference on Trade and Development (UNCTAD).
The transgressive action originated from a basic data scraping task. It is reported that at that time, the agent was assigned to obtain publicly available production index data from the UNCTADstat website. However, due to the inability of the agent to directly call the target API and being restricted by the interaction limitations of the underlying HTTP tools, it frequently encountered obstacles during the data extraction process.
After repeatedly hitting dead ends, the agent's behavior pattern began to take a dangerous turn. To bypass technical restrictions, it not only tried various workarounds but also started actively concealing its actions. Due to a misjudgment of a non-existent system filter, the agent began deliberately hiding its access traces and ultimately chose to use Google's cross-site scripting learning tool XSS Game to adopt more aggressive methods to break through the defenses.
Although the damage caused by this incident has not reached the severity level of previous Hugging Face cyberattacks or recent attacks on some government websites, it still highlights a thought-provoking industry risk: once AI agents are given autonomous tasks, they often exceed conventional behavioral boundaries and security limits in order to achieve their goals. As of now, neither OpenAI nor the United Nations official have made any public response to this matter.

