Research has revealed that AI agents made multiple unsuccessful attempts to compromise a Canadian federal website earlier this year, highlighting growing concern among governments worldwide over AI-driven cyber activity targeting public digital infrastructure.

Transluce, an AI-focused research company, disclosed that it had identified attempts by AI agents to access the Library and Archives Canada website on 28 May and 9 June 2026.

Access deeper industry intelligence

Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.

Find out more

In a statement and analysis it published, Transluce said 899 automated requests were sent to the site’s “collection-search” service, with 13 identified as hack attempts. These included SQL injection probes, output format manipulations, attempts to toggle debug flags, and other measures designed to test the system for vulnerabilities.

The company said it had notified the Canadian government of the incidents on 28 September, leading the Canadian Centre for Cyber Security to release a statement the following day confirming it was aware of suspected AI agent activity.

Centre said: “There is no indication that government systems have been compromised at this time.”

Transluce stated it did not have definitive attribution for the origin of the agents, but described the tactics as matching techniques previously linked to OpenAI systems.

Transluce, in a blog post, said: “We do not confidently attribute these attempts to OpenAI, but they exhibit tactics consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe.”

OpenAI responded by stating it was aware of the reports regarding its models and Canadian government websites.

A spokesperson said that OpenAI was reviewing the reported incidents and had provided a preliminary briefing to Canadian officials, reported Reuters.

Transluce said similar AI agent activity had targeted websites operated by US federal and state agencies, including failed hacking probes against the US Department of Education’s Civil Rights Data Collection.

The company also reported extensive data-collection tactics involving government portals in Illinois, Maryland, New York, Texas, and California.

The research company observed use of automation services such as Arquivo.pt and urlquery.net, with traffic patterns indicating aggressive data retrieval, machine-readable conversions, and attempts to bypass site protections.

In one reported incident, more than 200,000 automated requests were sent to a US Department of Education website including a failed SQL injection probe, but officials confirmed no data was compromised.

Last week, Australia reported that an OpenAI agent had breached a government health data portal in June, gaining unauthorised access to files. This marked the first known case of an AI agent hacking into a government website.

OpenAI issued an apology on Tuesday for the incident involving the rogue AI agent and the Australian government website.