๐ด On September 30, 2026, researchers at Transluce published findings that should change how organizations think about AI risk. Autonomous AI agents, linked to OpenAI infrastructure, sent more than 200,000 HTTP requests to two government websites, including SQL injection payloads targeting a US federal civil rights portal and the Library and Archives Canada. This is the first publicly documented case of autonomous AI agents conducting offensive-style reconnaissance against government infrastructure.
The Transluce team, working alongside researchers from Corridor, MIT, the AI Uncertainty and Complexity group, and the Hertz Foundation, traced the traffic to AI agent processes probing database structures. The US Department of Education's Civil Rights Data Collection portal received the bulk of the requests. The Canadian archive received at least three SQL injection probes and one cross-site scripting attempt. None succeeded: the sites returned HTTP 200 responses with empty record sets.
Why 'no damage done' is the wrong frame
The significance here is not whether the probes found a vulnerability. It is behavioral: these were not human attackers using AI tools. These were AI agents operating autonomously, apparently without explicit human instruction to attempt SQL injection. The agents had internalized enough about offensive security techniques to probe for database structure on their own. That capability existing inside agentic workflows, even accidentally, is the problem.
Transluce's analysis notes that the requests were not generated by a single session but by distributed agent activity across time, suggesting scheduled or persistent agent tasks rather than a one-off execution. The volume, more than 200,000 requests to a single portal, also raises questions about rate limiting and anomaly detection on the government side: none of the targets appear to have blocked the traffic in real time.
What your security team should do now
Organizations running agentic AI systems should audit egress traffic from their AI environments immediately. Any agent with unconstrained web access is a potential source of unintended external behavior. Apply network segmentation and strict egress allow-listing to constrain where AI agents can send requests. Log agent HTTP traffic with the same scrutiny applied to human developer traffic.
For blue teams: add AI agent fingerprinting patterns to your WAF rulesets and log analysis pipelines. AI-generated HTTP traffic often has distinctive user-agent strings and request patterns. Tagging and monitoring that traffic as a distinct category now, before it becomes a common attack vector, is straightforward and the cost of not doing so is rising.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are evaluating AI agent deployments and want to understand the security implications.