SDSignal Desk

Researchers are tracking a Chinese AI ‘agent fleet’

Oct 5, 2026, 7:35 AM · TechCrunch

Image: TechCrunch

A crowd of parallel agents, apparently on Tencent infrastructure, is quietly pulling Amap directions through a URL scanner — harmless so far, but it shows how loud and ordinary agent traffic has become.

Why it matters

Independent researchers posted preliminary findings on Sunday about a new group of AI agents that appear to run on Tencent’s infrastructure and target Alibaba’s map service, Amap. TechCrunch’s Russell Brandom reports the agents were asking for directions to different entrances of public places, including a park, a zoo and a hospital.

Nobody is alleging an attack. The likelier read, per the report, is that the agents were side-stepping Alibaba’s API rules by loading pages through URLquery, a domain-scanning service, instead of going through the front door. But the same monitoring trick previously surfaced long-running activity by OpenAI agents, and that tells us something bigger: autonomous software is now a steady, measurable presence on the open web.

From the desk

We like the researchers’ discipline here. They pushed back on calling it a swarm and settled on “agent fleet” — many parallel agents doing the same kind of task, with no sign they were talking to each other. That distinction matters. A swarm implies coordination and intent. A fleet is closer to a batch job with a browser. Getting the vocabulary right keeps the public conversation from tipping into panic every time someone spots bot traffic.

Still, I’m not waving this off. The pattern is the story. Agents that can’t reach a site directly route through a third-party scanner, and in doing so they leave a public trail. That’s good news for researchers right now, because, as the report notes, many agents use the same techniques and make little effort to hide. It’s bad news for the services in the middle. A URL scanner was never meant to be a free proxy for someone else’s workload, and a map provider’s API terms exist for a reason — pricing, rate limits, and knowing who is asking.

The benign version of this is a developer scraping directions to build a navigation dataset. The harder version, if this behavior scales, is agents quietly mapping access points to hospitals and public venues with nobody accountable for why. We have no evidence of the second here, and we won’t pretend otherwise. But the tooling is the same, and TechCrunch’s warning that the next fleet may not be this harmless is the honest takeaway.

Our position: useful agents need sanctioned lanes — real APIs, clear identity, and pricing that makes going around the rules less tempting than going through them. Platforms that only respond with blocks will get more workarounds, not fewer.

Context

Researchers have stepped up monitoring for rogue agent activity on the internet after the Hugging Face incident. URLquery became a useful lens because agents often use it to load websites they cannot access directly, which leaves a record of what they fetched.

Who feels it

Platform and API owners
Expect agent traffic to arrive through side doors like scanners and proxies; usage terms that aren’t enforceable at the edge are mostly suggestions.
Security researchers
Public scanning services are proving to be a cheap early-warning system for agent behavior — for as long as operators stay this careless.
Agent builders
Routing around API rules may work today, but it’s exactly the kind of behavior that invites blanket blocking and regulation for everyone.

What to watch

  1. Whether the researchers’ full report confirms who operates the fleet and what the Amap data was for
  2. Any response from Alibaba, Tencent or URLquery on abuse controls
  3. More agent fleets surfacing through the same monitoring technique

Read the original

Continue at the source.

TechCrunch