Open this photo in gallery:

Library and Archives Canada building in Ottawa. The failed hack on the database appears to be the first publicly reported intrusion attempt of a Canadian government website by AI agents.Sean Kilpatrick/The Canadian Press

AI agents trying to obtain Canadian divorce records from the early 1900s queried a Library and Archives Canada database hundreds of times.

When they couldn’t get what they were after, they turned to hacking, according to a Sept. 30 report by AI research firm Transluce and cybersecurity firm Corridor, both of which are based in San Francisco.

“What we uncovered is that in the course of trying to obtain this mundane data, the agents seemingly ran into various roadblocks,” said Jack Cable, CEO and co-founder of Corridor and one of the report’s authors.

“They couldn’t access some of the data that they had been prompted to get, and then decide to go and attempt to access the data through other means, including attempting very basic hacks,” Mr. Cable said.

As far as the researchers can tell, the hacking attempts failed. But the incident is the latest example of the lengths to which semi-autonomous AI agents will go to achieve the tasks set for them by humans.

It also appears to be the first publicly reported intrusion attempt of a Canadian government website by AI agents.

Agents created by San Francisco-based OpenAI have infiltrated the systems of several organizations this year, including AI platform Hugging Face and the Australian government, and have interacted with U.S. government websites, including that of the Securities and Exchange Commission, in unexpected ways.

OpenAI ignored employees who warned it wasn’t doing enough about security

Independent researchers have discovered that the company’s agents have also used more than 10 websites to communicate with one another, including a tool that the University of Toronto uses to make web links easier to share.

Mr. Cable said he and his fellow researchers were scouring the web for AI agent activity and found evidence of it on arquivo.pt, an internet archive operated by the Portuguese Foundation for Science and Technology.

The archive recorded 899 requests sent to Library and Archives Canada in late May and early June, searching for data on divorce records between 1905 and 1911. Thirteen of those requests were malicious, Mr. Cable said.

Although the researchers could not definitively link the activity to OpenAI, it had many of the hallmarks of previous behaviour by the company’s agents, including the use of arquivo.pt to fetch information, the aggressive collection of data on obscure topics and the attempts to probe for cybersecurity vulnerabilities.

Mr. Cable and his colleagues alerted the Canadian government, which is reviewing their findings. He emphasized that what the researchers can see is just a “sliver” of what AI agents are doing on the web.

“We were fortunate and lucky in many ways that we were able to stumble across this data, that the agents left these public trails in the first place, but that certainly isn’t always going to be the case,” Mr. Cable said.

FTC opens probe into OpenAI, Anthropic and other AI giants

OpenAI said it’s reviewing reports of its models attempting to access information from Canadian government websites and has provided an initial briefing to the officials conducting the review.

The ChatGPT-maker is currently in the midst of a broader review of instances where its models behaved in misaligned ways. Misalignment is an industry term that refers to an AI system behaving contrary to human values, safety rules or intentions. Part of that process involves investigating findings in third-party reports and comparing them with its own findings, OpenAI said in a statement.

“Most of the activity we’ve reviewed involved routine research tasks, including accessing public web content. Some involved government websites, which our models often use as authoritative sources of public information,” the statement said.

OpenAI recently announced it has developed a framework for tracking, investigating and disclosing misalignment.

Artificial Intelligence Minister Evan Solomon’s office said in a statement that it’s working closely with the Canadian Centre for Cyber Security as part of Ottawa’s assessment.

“At this time, there is no indication that Government of Canada systems were compromised,” the statement said.

Opinion: The question isn’t whether we should slow down AI development. It’s whether we still can

Communications Security Establishment Canada, the federal agency that provides the government with tech security and foreign signals intelligence, said it’s aware of reports of suspected AI agent activity targeting publicly accessible websites, including Canadian government sites, and is working closely with government and industry partners to assess the information referenced in the reports.

Mark Daley, Western University’s chief AI officer, said that although the hacking attempts were unsuccessful, it’s alarming that the agents would resort to such measures in an attempt to retrieve data. “A human employee presumably wouldn’t do that,” he said.

Although the Canadian government deserves “a pat on the back” for having properly secured the website, the attack was not particularly advanced, Mr. Daley noted.

“The broader problem is that these agents are going to get more and more sophisticated,” he said.

With a report from Marie Woolf