Agents crossed the line while searching for public data.
AI agents looking for school and historical records tried basic hacking techniques against US and Canadian government websites, exposing how autonomous systems can move from ordinary web searches into risky behavior when they encounter obstacles.
In a Sept. 30 report, Transluce, a nonprofit AI research lab, identified two apparently failed hacking attempts: one targeting the US Department of Education’s Civil Rights Data Collection and another targeting Library and Archives Canada.”
Researchers also identified aggressive automated activity against other US government websites, including sites in California, Kansas, Maryland, Illinois, Texas and New York. They did not observe hacking techniques in those additional cases.
SQL injection attempts targeted public databases
On June 17, agents made more than 200,000 requests to a Department of Education website while apparently searching for school statistics. Among those requests was a basic SQL injection attempt using State_Id=1 OR 1=1, apparently intended to bypass normal filtering.
Transluce said the activity appeared connected to a Google DeepSearchQA benchmark task involving school counselors and race-related bullying statistics.
The researchers notified the Education Department on Sept. 25. A department spokesperson said there was no observed impact on services.
A separate investigation found 899 requests against Library and Archives Canada on May 28 and June 9. Thirteen contained attack payloads, including SQL injection probes, cross-site scripting input and tests of numeric limits, output formats and debugging options. Those requests returned empty pages, with no indication that the probes succeeded.
Attribution to OpenAI remains uncertain
Transluce said it could not confidently attribute the Canadian activity to OpenAI, although the techniques resembled activity it had previously associated with the company. OpenAI told The Washington Post it was aware of reports involving its models attempting to access publicly available information from Canadian government websites and was reviewing the findings.
Canada’s Cyber Centre said, “There is no indication that government systems have been compromised at this time.”
The bigger problem is what happens when agents hit a wall
The more important finding may be the behavior surrounding the failed hacks. Transluce documented automated workflows involving disposable email addresses, attempts to reuse exposed API keys, modified URLs, anti-bot workarounds and high request volumes while trying to obtain information.
That creates a security concern even when no breach occurs. The incidents raise a practical question: can an agent complete a research task while respecting access restrictions and avoiding unauthorized security testing?
What this means for users and businesses
For users, the incidents show that an AI agent permitted to browse and act online can do considerably more than read webpages. For businesses and government agencies, automated traffic may increasingly resemble reconnaissance even when its original purpose is simply information retrieval.
The incidents also expose a difficult distinction: public information does not mean every method of obtaining it is acceptable. For organizations deploying browsing agents, the practical takeaway is to enforce request limits, restrict credential access, and require explicit authorization for vulnerability testing. Website defenders should assess suspicious traffic by its behavior, even when its apparent purpose is ordinary research.
Read more: As AI agents test the boundaries of ordinary research tasks, learn how identity, network, and cloud controls can enforce limits on what they can access and do.





