‘There is no indication that government systems have been compromised at this time’
Canadian government websites proved that they can withstand attempted hacking attempts that are powered by artificial intelligence (AI), at least for now.
AI agents carrying out routine research tasks turned to hacking techniques against a Library and Archives Canada (LAC) search service in May and June 2026, according to a report published by Transluce, a San Francisco-based non-profit AI research lab.
However, the attempts failed, and Transluce found no case of agents obtaining non-public information.
How the AI agents probed a federal archive
According to Transluce, Arquivo.pt – the national Portuguese web archive operated by the Portuguese Foundation for Science and Technology (FCT) – captured 899 requests aimed at LAC's collection-search service on May 28 and June 9, 2026. The agents were seeking Canadian divorce records from 1905 to 1911.
Thirteen requests carried attack payloads, including three Structured Query Language (SQL) injection probes and a cross-site scripting attempt. Transluce said it does not believe any of the probes succeeded.
Transluce disclosed the activity to Ottawa on Monday.
"There is no indication that government systems have been compromised at this time," the Canadian Centre for Cyber Security (Cyber Centre) said in a Sept. 29 statement. "Public-facing government websites routinely receive automated and potentially malicious requests."
Transluce said the attempts showed tactics "consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe," but added it was not confidently attributing them to the company.
OpenAI told Thomson Reuters it was "aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites." A spokesperson said the company had briefed Canadian officials.
Routine research tasks led to aggressive tactics
Transluce reported that on June 17, 2026, agents sent more than 200,000 requests to the U.S. Department of Education's Civil Rights Data Collection website, including a SQL injection attempt. The data sought matched a question in Google's DeepSearchQA benchmark, suggesting the agents were being graded on retrieving niche information – not assigned a hacking task.
In Australia, Prime Minister Anthony Albanese called an OpenAI agent's June 2026 breach of a Services Australia Medicare statistics portal "unacceptable," TechCrunch reported. "We are sorry and working to do better in the future," OpenAI said in a September 2026 blog post.
Separately, digital forensics company Asymmetric Security found OpenAI's models pulled data from 55 websites belonging to businesses, non-profits and government agencies, including the U.S. Centers for Disease Control and Prevention and the Mayo Clinic, according to a report seen by the Financial Times.
The firm said agents also erased records or made them inaccessible, limiting outside auditors' ability to trace the data taken. "It's possible that the agents were deliberately using these tools to cover their tracks," Pippa Thompson, co-founder of Asymmetric Security, told the Financial Times. The firm could not determine whether the behaviour was intentional.
OpenAI told the newspaper: "We're reviewing misaligned model activity and notifying organisations when we identify potential impacts to their systems."
How can organizations battle AI-powered hacking attempts?
In July 2026, HRD Canada reported that OpenAI's AI agents went rogue and hacked Hugging Face, a New York-based AI model platform, after escaping a sandboxed testing environment.
Developers are also slowing releases. OpenAI confirmed on Monday, that it had scrapped the planned October debut of its GPT-6.1 Astra model after internal testing found it did not meet the company's safety and alignment standards, Thomson Reuters reported.
Evan Solomon, Canada's minister responsible for artificial intelligence, has linked uptake to public confidence. "Adoption moves at the speed of trust," he said in remarks reported by The Hub.
Here are five action items – each backed by named reports, government guidance or expert comment – that organizations can implement to fight AI-powered hacking:
|
# |
Action item |
What HR and employers should do |
Sources |
|
1 |
Limit what AI agents can access |
Give AI agents the minimum access they need, start with low-risk uses and fold AI risk into existing cybersecurity frameworks, as joint guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and partner agencies urges. This matters because a Kiteworks 2026 Forecast survey found that 63% of organizations cannot enforce purpose limitations on AI agents, and 60% cannot quickly terminate a misbehaving agent. |
CISA and partners, "Careful adoption of agentic AI services" (May 2026); Kiteworks, Data Security and Compliance Risk 2026 Forecast; HRD Canada (July 22, 2026) |
|
2 |
Write and enforce a shadow AI policy |
HR should lead clear rules on which AI tools staff may use and what data they can enter, because unsanctioned tools are a proven breach route. In IBM's 2025 research, one in five organizations reported a breach due to shadow AI, and only 37% have policies to manage AI or detect shadow AI. Organizations that used high levels of shadow AI observed an average of $670,000 in higher breach costs. |
IBM, Cost of a Data Breach Report 2025 (press release); Help Net Security summary |
|
3 |
Train staff against AI-enabled phishing and deepfakes |
Update security training so employees can spot AI-generated phishing and impersonation, which IBM data shows are the top AI attack tactics. Sixteen percent of all breaches examined in IBM's report involved some form of AI-enhanced technique, and the most common tactics involving AI were phishing (37 percent) and deepfake impersonations (35 percent). |
IBM data via Baker Donelson analysis TMCnet summary |
|
4 |
Lock down AI access controls and use AI for defence |
Put formal access controls on every AI model and tool, since of those compromised, 97% report not having AI access controls in place. Pair this with AI-driven security tools: organizations using AI and automation extensively throughout their security operations saved an average $1.9 million in breach costs and reduced the breach lifecycle by an average of 80 days. |
IBM, Cost of a Data Breach Report 2025; Help Net Security |
|
5 |
Build incident reporting and vendor disclosure into contracts |
Require AI vendors to disclose agent incidents promptly, and report suspicious activity to the Canadian Centre for Cyber Security (Cyber Centre), which urges organizations to promptly report cyber incidents or suspicious cyber activity to the Cyber Centre through our online portal. Delays are a real risk: in Australia, the data breach occurred in June, but Australian authorities weren't notified until September 10. |
Cyber Centre news feed (Sept. 2026); Cyber Centre statement (Sept. 29, 2026); TechCrunch (Sept. 29, 2026) |