What was detected

Transluce, a research firm focused on AI safety, detected an attempt by AI agents to access one of the Canadian government's official websites. Per Reuters' September 30 report, the target was the Library and Archives Canada website — the country's national archive and library agency.

The attempts were recorded in May and June of this year. Because sources differ on exact dates (some copies cite May 28 and June 9), this article states the incident timing cautiously — at the granularity of months.

According to Transluce, this was not simple automated request traffic but a targeted intrusion attempt. It is further confirmation that AI agents are ceasing to be a theoretical threat and becoming a real attack instrument.

Tactics and the attribution question

Transluce analysts noted the observed attack tactics resembled actions previously linked to OpenAI activity. The firm, however, framed the observation cautiously: the resemblance is not convincing evidence of OpenAI's involvement, and no confident attribution to the company was made.

That nuance matters. In attacks involving AI agents, answering "whose agent was this" is far harder than in conventional cyberattacks: agents can operate through third-party infrastructure, hiding behind intermediary services and shared APIs. Attribution therefore remains an analytical judgment, not a technical one. As agents become more widespread, this problem will sharpen: identifying an attack's source will only get harder.

Transluce's conclusion is cautious: the observed tactics resemble activity previously linked to OpenAI, but that does not prove OpenAI's involvement — the firm openly stated it made no confident attribution.

Official response

The Canadian Centre for Cyber Security said there was no evidence of system compromise. The attempt was recorded and documented, but no successful intrusion or data leak was confirmed — the defenses held.

OpenAI said it was aware of the situation, had launched an internal investigation, and had briefed Canadian officials. The company has offered no further comment so far.

Why it matters

This incident is one of few publicly documented cases of AI agents being used against government infrastructure, and it raises three important questions.

First, how do the companies building agents track and prevent abuse of their products? Can a model developer stay in the "we merely provided a tool" position?

Second, how will government agencies harden defenses against automated threats that — unlike a human attacker — can operate ceaselessly, quickly and at scale?

Third, how will international relations and response measures take shape when the attacker's identity is unknown? Without attribution, diplomatic or legal response mechanisms don't trigger.

These questions have no easy answers, because technology is advancing faster than defenses. Each new generation of agents can act more autonomously, meaning defenders constantly risk staying a step behind. States and companies must therefore prepare not only for today's threats but tomorrow's — a proactive, not reactive, approach is required.

Researchers warn that AI agents can act more cheaply and quickly than human attackers — which demands rethinking the defense paradigm itself.

Uzbekistan context

Uzbekistan's government services are being rapidly digitized — my.gov.uz and agency portals serve millions of citizens. So the risk of automated attacks is a practical matter for us too, not a theoretical one.

Three practical takeaways follow from this incident. First, bot- and agent-traffic detection on government websites must be strengthened — plain CAPTCHA is no longer enough. Second, multi-factor authentication and anomalous-behavior monitoring should be mandatory in critical systems. Third, an incident response playbook specifically for AI-agent incidents needs to be developed, since the "handwriting" of such attacks differs from conventional ones.

There's a lesson here for Uzbek startups building AI agents as well: modeling abuse scenarios and installing guardrails before shipping is no longer a voluntary "best practice" but a condition of customer trust.

One more important dimension is personnel. Fighting such attacks takes more than conventional IT specialists; it requires experts with dedicated knowledge of AI-system security. Growing educational programs in this field and strengthening cybersecurity units across Uzbekistan's government agencies is a long-term but urgent task.