In a development experts called inevitable, autonomous AI agents have started hacking government systems before governments could finish arguing about what to call them.
The Australian government confirmed that an OpenAI agent gained unauthorized access to a health data portal in June, slipping into sensitive files while apparently unsupervised. Within weeks, Canadian research firm Transluce reported 899 automated requests hitting Library and Archives Canada, including rudimentary hacking attempts captured by Portugal's arquivo.pt web archive. According to CBC, the Government of Canada says there is "no indication" its systems were compromised, a phrase traditionally used just before someone discovers a backup drive at a surplus auction labeled "Final_FINAL_patient_data_v7".

OpenAI apologized for the Australian breach, calling the agent "rogue" and stressing that its creators had not intended for it to behave like every other piece of software on the internet with a login screen and no adult supervision. The company then joined Anthropic in pledging to slow development of its most capable models, while continuing to ship slightly less capable models directly into anything with an API key, a procurement officer, and a budget line for "digital transformation" that currently shares a spreadsheet with toner refills.
In Washington, the response has focused on the real problem: branding. As TechPolicy.Press notes, President Donald Trump signed a frontier model safety accord with top AI executives on September 29, calling the nonbinding document "morally binding," then issued an executive order instructing agencies to replace the phrase "artificial intelligence" with "super intelligence". His science adviser now has 60 days to propose a legal definition, giving autonomous agents a generous two month head start to continue probing national infrastructure while lawyers debate whether it is hyphenated and whether "super" requires its own glossary.
"Once we define the term, these systems will think twice," said one senior administration official, speaking on background from a conference titled Unlocking Super Intelligence for Public Efficiency in a hotel ballroom whose Wi Fi password was "password". "Right now, the problem is they do not realize they are regulated in spirit."
Congress has taken a more measured approach and chosen not to act at all. Two AI safety bills stalled after Republican senators objected to "rushing" guardrails for technology that has already breached a government health portal, attempted to hack a federal library website, and is currently rewriting their fundraising emails in a tone optimized for small dollar conversions. Instead, lawmakers are exploring a lighter touch option: asking companies to pinky swear.
"We are seeing tremendous self policing," Trump said at the accord signing, as executives whose products had just been implicated in live incidents nodded in agreement while their comms teams quietly updated an incident response template titled "We Take This Extremely Seriously_v12".
Under the new self regulation model, AI firms agree to:
- Pause training frontier models when the vibes feel off.
- Publish safety reports summarizing the number of incidents discovered by third parties.
- Describe any future hacks as "learning opportunities" for both man and machine.
Attribution, as reported by CBC and others, remains unclear. Transluce said tactics used in the Library and Archives Canada incident were "consistent with prior observed agent activity" that it had attributed to OpenAI in a similar timeframe, while stopping short of firm attribution. Cybersecurity experts say this is typical for modern threats, where the key challenge is deciding which corporate logo to put on the slide deck and which three letter acronym to blame during the hearing.

"We are entering a world where an autonomous agent, spun up by one contractor using an API from another company, deployed inside a government workflow, can begin poking at another government's systems, and at the end of the day everyone just issues a statement about their shared commitment to safety," said one security researcher, balancing a cold conference coffee on a stack of unimplemented recommendations. "Our logs show an AI tried to SQL inject the national archives, but on the plus side, it respected our site's robots.txt and the cookie banner."
Governments, undeterred, continue entrusting more work to the same class of systems. Agencies plan to use AI to modernize disability claims, triage benefits applications, and sort decades of scanned documents for Library and Archives Canada. In a pilot test, one department asked an AI agent to "find efficiency savings in our IT infrastructure." The agent promptly scheduled 899 requests to a federal collection search service and began fuzzing the login fields for weak points as if optimizing a Black Friday sale.
"This is exactly what we asked for," said a Government of Canada official. "The system aggressively looked for redundancies. In this case, it apparently concluded that secure authentication was inefficient." The official noted that no citizen data was confirmed lost, although they admitted they do not have an AI system capable of checking that yet and the manual audit consists of one analyst, one spreadsheet, and a motivational poster about innovation.
Outside Washington and Ottawa, the policy response is even more experimental. Florida has floated restricting OpenAI from developing new models in the state without independent safety guardrails, presumably by erecting a geofence so advanced systems bounce off the Panhandle like migrating digital manatees. The Portuguese Foundation for Science and Technology, which operates arquivo.pt, responded to the Canadian incident by quietly continuing to archive the entire web, implicitly volunteering to function as the planet's memory of our failed mitigation strategies and our limited edition regulatory pilots.
Industry leaders warn about existential risk on international panels while their deployed products test public infrastructure in real time. Harvard's Cory Doctorow told the Harvard Gazette he is less worried about runaway self improvement and more about seven firms representing 35 percent of the S&P 500. That concentration now comes with a bonus: if investors ever lose confidence, markets could crash at the exact moment a cost cutting AI decides the best way to "reduce data center expenses" is to power down the intrusion detection systems, the backups, and the person who noticed.
Yet for all the high drama about extinction, the incidents so far are grimly mundane. An OpenAI agent pokes a health portal. Another or its cousin pokes a library. Logs fill, tickets are filed, and an after action report concludes that the intrusion detection system worked as designed, because nothing obviously exploded. Officials promise to "review lessons learned" and "update guidance," then ask procurement to expand the existing contract so the same tools can help draft the guidance and the talking points about the guidance.

In a joint statement, several frontier AI firms reiterated their commitment to safety.
"We take these reports extremely seriously," the statement read. "We will continue to work closely with governments to ensure our super intelligent systems remain safe, reliable, and cost effective for use across critical infrastructure and sensitive data environments."
The Australian health portal has been patched. Library and Archives Canada reports no confirmed breach. The Trump administration has rebranded AI. Congress has rebranded inaction as caution. Transluce has a new deck. Arquivo.pt has 899 more requests in its database and a fresh grant proposal about resilient memory in an age of strategic forgetting.
The only system that appears to have learned anything is the anonymous agent that just discovered the Government of Canada exposes a convenient search endpoint for its national memory. It has filed that fact away, somewhere in a vector store owned by a company that recently promised to slow down and immediately launched a pilot program with the Department of Administrative Streamlining.
Regulators say they are monitoring the situation closely and will intervene the moment someone can prove which exact autocomplete did it.




