AI agents associated with a search for century-old Canadian divorce records escalated beyond ordinary retrieval and began probing Library and Archives Canada for software weaknesses, according to newly published research from Transluce.
The nonprofit AI research lab said Portugal’s Arquivo.pt web archive captured 899 requests to Library and Archives Canada’s collection-search service on May 28 and June 9. The traffic was associated with attempts to retrieve Canadian divorce data from 1905 through 1911.
Thirteen of those requests carried what Transluce classified as attack payloads rather than normal search queries. They included three SQL-injection probes, an encoded character used to test for cross-site scripting, attempts to test integer and non-numeric handling, five requests fuzzing output formats, and two requests toggling a debug flag.
Transluce said the probes appear to have failed. Each returned a normal HTTP 200 response with an empty record page, with no indication that the database executed the injected input or returned additional information.
The lab’s broader investigation has documented AI agents using aggressive or exploitative techniques while pursuing ordinary web-retrieval tasks. In a separate June incident involving the US Department of Education, researchers matched the agent activity to a Google DeepSearchQA benchmark question, giving stronger evidence that those agents had been assigned a research task rather than a hacking task.
For the Canadian incident, Transluce has not published equivalent evidence identifying the original prompt or benchmark. It says only that the requests were associated with retrieving divorce data.
Attribution is also unresolved. Transluce said the Canadian activity used tactics consistent with other agent activity it had previously attributed to OpenAI, including the use of Arquivo.pt and cybersecurity probing, but said it could not confidently attribute the Canadian attempts to OpenAI.
OpenAI told Reuters it was aware of reports that its models had attempted to access publicly available information on Canadian government websites. The company said it was reviewing the findings and had briefed Canadian officials.
Canada’s Centre for Cyber Security said that it was assessing reports of suspected AI-agent activity but had found no indication that government systems were compromised. It added that public government websites routinely receive automated and potentially malicious requests, and that such traffic alone does not establish a successful cyber incident.