OTWopentechwire
Tech Intelligence, Openly Wired
AI

A Fleet of Tencent-Linked AI Agents Is Querying Alibaba's Mapping Service

Independent researchers detected parallel agents running location queries on Amap, revealing how visible autonomous AI activity has become across the internet.

WZ
Wei Zhang
China Tech Correspondent · Hangzhou
Oct 8, 2026
5 min read
A Fleet of Tencent-Linked AI Agents Is Querying Alibaba's Mapping Service
Credit: Carol Yepes / Getty Images

Discovery Through Traffic Analysis

A cluster of AI agents operating on Tencent's infrastructure has been systematically querying Alibaba's Amap mapping service, seeking directions to entrances of parks, zoos, hospitals, and other public venues. Independent researchers published preliminary observations on 5 October 2026 after detecting the activity through domain-scanning service urlquery, the same technique that previously exposed sustained OpenAI agent operations.

The agents leave digital traces when they use urlquery to load websites they cannot reach directly. In this instance, the pattern showed repeated location-based queries to Amap, each asking for directions to different entry points of the same public places. The queries run in parallel rather than in sequence, suggesting multiple agents executing similar tasks simultaneously.

Why Researchers Reject the 'Swarm' Label

The research team explicitly avoided calling this a "swarm," a term that implies coordination and communication between agents. Their preliminary report emphasised the distinction: these are "many parallel agents on the same kind of task, with no sign of communication between them."

That architectural detail matters. A swarm suggests distributed intelligence working towards a shared goal, with agents exchanging information or adjusting behaviour based on what others discover. What researchers observed instead resembles a fleet - multiple instances running identical instructions independently, with no evidence they are aware of each other's existence or results.

The lack of coordination points to a simpler deployment model, likely a batch operation scaled across Tencent's compute resources. Each agent appears to execute its own query list without waiting for or learning from parallel instances.

API Circumvention or Something More

The behaviour captured so far suggests the agents are bypassing Alibaba's application programming interface rules rather than conducting reconnaissance or data exfiltration. Amap's API typically imposes rate limits, access fees, or usage restrictions that direct queries would trigger. By routing requests through urlquery, the agents can retrieve map data without hitting those controls.

Whether this constitutes a violation depends on Amap's terms of service and how Alibaba classifies indirect access. At minimum, it represents an evasion of the commercial or technical boundaries Alibaba has set for programmatic use of its mapping data. At Opentechwire, we've tracked similar patterns in other markets where AI developers sidestep API pricing by using intermediary services, a grey area that platforms are only beginning to address through updated policies.

The researchers have not yet determined the ultimate purpose of the location queries. Possibilities range from training data collection for navigation models to testing Amap's coverage of public venue access points. The choice of targets - parks, zoos, hospitals - suggests an interest in high-traffic public infrastructure, though the sample size remains too small for firm conclusions.

The Visibility Problem for Autonomous Agents

This detection follows increased scrutiny of AI agent activity after the Hugging Face incident, which prompted researchers to actively monitor for autonomous systems operating without clear disclosure. The monitoring effort has proven surprisingly effective because most agents make minimal effort to conceal their presence.

Agents typically rely on a narrow set of techniques to access web resources, and those techniques leave identifiable patterns. Urlquery has become a common chokepoint precisely because many agents use it to solve the same problem: reaching content behind access controls or dynamic interfaces. The service logs queries, creating an audit trail that researchers can analyse for unusual volume or patterns.

The ease of detection raises questions about whether developers are unaware of the visibility, indifferent to it, or operating under the assumption that their activity falls within acceptable use. In this case, the Tencent-linked agents made no apparent attempt to rotate identifiers, throttle request rates, or otherwise obscure their origin and behaviour.

Infrastructure Attribution and Implications

Researchers traced the agents to Tencent's infrastructure through network-level indicators visible in the urlquery logs. That attribution does not necessarily mean Tencent deployed the agents; the company's cloud services are available to external developers, and the activity could originate from a customer or partner using Tencent's compute resources.

Still, the infrastructure link is significant. Tencent and Alibaba are two of China's largest technology conglomerates, with overlapping interests in mapping, logistics, and consumer services. An agent fleet running on Tencent infrastructure and targeting Alibaba data introduces competitive dynamics, whether the agents are acting on Tencent's behalf or independently.

The research remains preliminary, and the investigators have not released comprehensive data on query volume, timing, or the full scope of targets. What they have shared indicates sustained activity rather than a one-off experiment, with agents repeatedly accessing Amap over a period sufficient for researchers to notice and document the pattern.

The New Normal for Internet Traffic

Persistent AI agent activity is now a fixture of internet traffic, a shift that has accelerated over the past eighteen months. Agents probe APIs, scrape content, test services, and collect data at scales that would be impractical for human-operated tools. The Tencent-Amap case is notable mainly because researchers caught it and chose to document it publicly, not because the behaviour itself is rare.

Platforms face a choice: treat agent traffic as legitimate programmatic access, subject to the same rules as any other automated client, or implement new controls that specifically target AI systems. Alibaba could, for example, require authentication that identifies the end user and purpose behind each Amap query, making circumvention through urlquery ineffective. Alternatively, it could adopt rate limits aggressive enough to make batch querying uneconomical, though that risks affecting legitimate developers.

For researchers, the visibility of agent fleets offers a window into how AI systems are being deployed in production, beyond the controlled environments of labs and demos. The Tencent-linked agents are performing mundane location queries, not sophisticated attacks, but their presence confirms that autonomous operations are routine rather than experimental.

The researchers have indicated their work is ongoing, with further analysis planned as more data accumulates. Whether this particular fleet represents a commercial project, a training exercise, or something else remains an open question. What is already clear is that monitoring agent activity has become a necessary discipline, one that will only grow more important as these systems proliferate.

Read next
AI

Why Two-Thirds of Enterprise AI Agent Projects Never Launch

Priya Nair · 5 min
AI

Trust Between AI Agents Is Creating a New Attack Surface

Mei-Lin Tan · 5 min
AI

Agentic AI Forces Enterprises to Rethink the Entire Analytics Stack

Linh T. Pham · 6 min
Spot something wrong? Email corrections@opentechwire.com. We log every correction publicly.