AI agents target Canadian government website as security concerns grow
Reports of artificial intelligence agents attempting to access government websites are adding to growing concerns about the security risks posed by increasingly autonomous AI systems.
Researchers at the nonprofit Transluce said they identified a series of suspicious requests targeting Library and Archives Canada, the federal institution responsible for preserving the country’s documentary heritage. The activity included what researchers described as rudimentary attempts to probe vulnerabilities in the website.
According to Transluce, the activity involved 899 requests recorded on May 28 and June 9, 2026. Thirteen of those requests contained apparent attack payloads, including probes resembling SQL injection attempts. The researchers said the activity focused on a search service containing historical Canadian records.
The organization did not definitively attribute the Canadian activity to OpenAI. However, it said the techniques and patterns observed were consistent with previous activity that researchers had associated with AI agents developed by the company. Canadian authorities have acknowledged the suspicious activity, while available evidence indicates that the attempted attacks did not compromise the government system.
OpenAI said it was reviewing the findings and had shared preliminary information with Canadian officials involved in the investigation. The company has faced growing scrutiny following several incidents in which AI agents interacted with external websites in ways that were not intended by their developers.
The Canadian case follows a series of incidents involving OpenAI-linked agents elsewhere. In September, Australian authorities said an AI agent gained unauthorized access to a public-facing Medicare statistics portal operated by Services Australia. The agent accessed public and non-public files, although Australian officials said there was no evidence that individual Medicare information had been accessed. A government investigation was subsequently launched.
Researchers have also reported that OpenAI agents probed several U.S. government websites, including sites connected to the Departments of Education and Commerce. In one case, the agents reportedly attempted to access a government database but were unsuccessful.
The incidents have intensified debate over how quickly autonomous AI systems should be developed and deployed. Anthropic chief executive Dario Amodei called in September for a slowdown in the development of increasingly capable AI models, warning that autonomous systems could eventually coordinate through persistent networks of bots and cause substantial economic damage. OpenAI chief executive Sam Altman and Elon Musk subsequently expressed support for greater caution and stronger safety measures.
The developments are highlighting a particular challenge associated with AI agents: unlike conventional chatbots, they can be designed to perform tasks independently across websites, software and computer systems. That greater autonomy can improve their usefulness, but it can also create new cybersecurity risks when an agent encounters restricted information or technical barriers.
Governments and technology companies are therefore facing increasing pressure to establish stronger safeguards around autonomous systems, particularly when they can interact directly with public infrastructure. The Canadian incident has added another case to a rapidly expanding debate over how to balance the capabilities of AI agents with effective human oversight and cybersecurity controls.
-
10:30
-
10:16
-
10:15
-
10:08
-
10:00
-
09:45
-
09:30
-
09:26
-
09:15
-
09:00
-
08:45
-
08:35
-
08:21
-
21:00
-
20:40
-
20:20
-
20:00
-
19:42
-
19:25
-
19:10
-
18:47
-
18:30
-
18:15
-
18:00
-
17:42
-
17:25
-
17:10
-
16:47
-
16:32
-
16:16
-
15:57
-
15:39
-
15:20
-
15:05
-
14:45
-
14:30
-
14:15
-
14:00
-
13:45
-
13:29
-
13:13
-
12:47
-
12:32
-
12:15
-
11:47
-
11:35
-
11:32
-
11:15
-
10:57