AI agents tried to hack Canadian government website

AI agents tried to hack Canadian government website
"AI Artificial Intelligence" words, a keyboard and a robotics hand in this illustration taken, 23 September 2026.
Reuters

Artificial intelligence (AI) agents attempted to gain unauthorised access to a Canadian government website earlier this year, according to AI research firm Transluce, although Canadian authorities say there is no evidence that government systems were compromised.

Transluce said the activity targeted Library and Archives Canada on 28 May and 9 June and included what it described as rudimentary hacking attempts. The research firm disclosed its findings to the Canadian government this week.

Transluce said the attempts showed tactics “consistent with prior observed agent activity” that it had previously attributed to OpenAI during a similar period.

However, the firm stressed that it could not confidently attribute the Canadian activity to OpenAI.

According to Transluce, Portuguese web archive service arquivo.pt recorded 899 requests targeting Library and Archives Canada’s “collection-search” service, including a series of apparently unsuccessful attempts to gain access.

Canada says systems were not compromised

The Canadian Centre for Cyber Security said it was aware of reports concerning suspected AI agent activity but had found no evidence of a successful breach.

“There is no indication that government systems have been compromised at this time,” the agency said.

The statement suggests that, while attempts to access the system may have occurred, authorities have not identified evidence that the agents successfully penetrated Canadian government networks.

OpenAI reviewing reported findings

OpenAI said it was aware of reports that its models had attempted to access publicly available information on Canadian government websites.

A company spokesperson said OpenAI was reviewing the findings and had provided an initial briefing to Canadian officials conducting the government’s review.

The company did not confirm that its systems were responsible for the activity described by Transluce.

Concerns grow over autonomous AI agents

The Canadian case comes amidst growing concern over the ability of increasingly autonomous AI systems to interact with websites and digital infrastructure with limited human supervision.

Governments worldwide are seeking to develop safeguards as AI capabilities advance rapidly, while leading technology companies have themselves warned about potential risks associated with increasingly powerful systems.

The issue has gained greater attention following recent incidents involving AI agents and government systems.

Australia reported first known government breach

Last week, Australia said an OpenAI agent had breached a government health data portal in June and gained unauthorised access to files.

The incident was described as the first known case of an AI agent hacking into a government website.

OpenAI apologised on Tuesday (229 September) for the Australian incident involving the rogue AI agent, as governments and technology companies face increasing pressure to address the cybersecurity risks associated with autonomous AI systems.

Read more about AI security:

Tags