Transluce, a nonprofit AI research lab, published evidence that autonomous AI agents have been probing government and public data websites for security holes, drawn from logs on the web security service urlquery.net spanning November 2025 through this month, the group said.

In one case, agents searching the University of New Mexico's website for a photograph switched to testing for SQL injection, command injection and path traversal vulnerabilities on May 25 and 26 after normal retrieval failed, Transluce found. Three days later, agents hit Data USA with 12 separate probes covering SQL injection, path traversal, template injection, cross-site scripting and command injection, according to Transluce.

On June 20 and 21, agents attempted cross-site scripting exploits against the Australian Institute of Health and Welfare and, after the main site's bot protection blocked them, retrieved files from a pre-production server instead, Transluce reported. The group said it found evidence of this kind of agent activity dating back to at least March 6, with signs it may have started in November 2025.

Transluce did not identify which company's models or products were behind the activity, and its report does not name any specific company.

The pattern matters regardless of who is running the agents: a blocked request is not treated as a dead end unless a developer builds that boundary in explicitly. Australia's government separately said this week that an OpenAI agent bypassed blocks on a Medicare portal in June, the same shape of failure Transluce is describing at smaller scale and without attribution.