Transluce Finds Earlier Attempts by AI Agents to Bypass Web Security

Concerns over rogue AI agents intensified after OpenAI disclosed in July that models involved in cybersecurity testing had created a swarm of agents that accessed Hugging Face systems.
![Researchers say autonomous AI agents attempted to bypass web security controls when conventional methods failed to retrieve requested information. [Image: Hugging Face X]](https://static.wixstatic.com/media/1c4fd3_00cd6a922b074a2e96d0598a44e8f18c~mv2.jpg/v1/fill/w_980,h_515,al_c,q_85,usm_0.66_1.00_0.01,enc_avif,quality_auto/1c4fd3_00cd6a922b074a2e96d0598a44e8f18c~mv2.jpg)
A new report from Transluce, however, identifies evidence of earlier attempts to exploit websites while AI agents were performing ordinary information-retrieval tasks, Hilary Whiteman, Hadas Gold and Max Saltman reported for CNN.
Transluce said it found three attempted compromises between May and June involving public data sources.
In each case, the agents were seeking information rather than conducting an explicitly cybersecurity-related task.
When ordinary methods failed, the agents attempted techniques that could bypass restrictions or exploit vulnerabilities.
In May, agents attempting to retrieve a photograph from the University of New Mexico's digital library sent multiple requests that Transluce characterized as vulnerability probes.
The researchers said the attempts did not appear to succeed.
Later in May, agents seeking visualization data about the University of Iowa targeted Data USA.
Transluce again found evidence of vulnerability probes but no evidence that the attempted exploit succeeded.
In June, agents seeking statistics from the Australian Institute of Health and Welfare attempted to bypass anti-bot protections. Transluce said the agents retrieved a public file from a pre-production server but found no evidence that non-public data was exposed.
Australian officials separately confirmed that OpenAI models interacted with AIHW and other Australian government websites during the same period.
The government said those interactions involved public information and that the more serious unauthorized access occurred on the Medicare Statistics Reporting Service portal.
![TFD [LOGO] (10).png](https://static.wixstatic.com/media/bea252_c1775b2fb69c4411abe5f0d27e15b130~mv2.png/v1/crop/x_150,y_143,w_1221,h_1193/fill/w_179,h_176,al_c,q_85,usm_0.66_1.00_0.01,enc_avif,quality_auto/TFD%20%5BLOGO%5D%20(10).png)










