Communications Security Establishment says there is "no indication that government systems have been compromised at this time" and that public-facing government websites routinely receive automated and potentially malicious requests
Communications Security Establishment CanadaCanada's national signals intelligence and cyber security agency, in a statement published on the website of its Canadian Centre for Cyber Security
On September 29, 2026 the Communications Security Establishment published a statement on its Cyber Centre's website saying it was "aware of reports identifying suspicious activity, including suspected AI agent activity, targeting publicly accessible websites, such as the Government of Canada." It said "There is no indication that government systems have been compromised at this time." It said that public-facing government websites "routinely receive automated and potentially malicious requests" and that such activity "does not, on its own, indicate a successful cyber incident." The statement says the Cyber Centre is working with government partners to assess the information in the reports. It does not mention Library and Archives Canada, Transluce or the requests.
Responding to
The Communications Security Establishment said on September 29, 2026 that there is no indication that government systems have been compromised at this time, and that the routine automated and potentially malicious requests that public-facing government websites receive do not, on their own, indicate a successful cyber incident.
“We are aware of reports identifying suspicious activity, including suspected AI agent activity, targeting publicly accessible websites, such as the Government of Canada. There is no indication that government systems have been compromised at this time. Public-facing government websites routinely receive automated and potentially malicious requests. Such activity is an ongoing feature of the online environment and does not, on its own, indicate a successful cyber incident.”
Official statement
Reporting

Where this statement fits
Did AI agents attempt to hack Library and Archives Canada, as Transluce reports?
On September 30, 2026, the AI research lab Transluce reported that on May 28 and June 9, 2026, the Portuguese web archive Arquivo.pt captured 899 requests to the "collection-search" service of Library and Archives Canada, "including a series of apparently failed rudimentary hacking attempts." Transluce says 13 of the requests carried what it calls attack payloads, says it does not believe the probes succeeded, and says it does not confidently attribute them to OpenAI, although it says they show tactics consistent with activity it has attributed to OpenAI. On September 29, the Communications Security Establishment, through its Cyber Centre, said there was "no indication that government systems have been compromised at this time" and that public-facing government websites routinely receive automated and potentially malicious requests, which do not, on their own, indicate a successful cyber incident. Evan Solomon, Canada's Minister of Artificial Intelligence and Digital Innovation, posted that there was no indication of compromise or of any data being accessed. OpenAI said it was aware of reports of its models attempting to access publicly available information from Canadian government websites, and that it is reviewing the findings and has briefed Canadian officials. The disputed question is whether the requests were hacking attempts, as Transluce reports. As of October 1, 2026, the Canadian government's assessment and OpenAI's review were open, and we did not find a public statement from Library and Archives Canada.
Source and context
Official statement
About this source
The statement is published on the website of the Canadian Centre for Cyber Security, which is part of the Communications Security Establishment Canada (CSE), and its byline reads "From: Communications Security Establishment Canada." Press reports call it the Cyber Centre's statement, and BetaKit credits it to CSE. It is dated September 29, 2026, one day before Transluce's report was published, and Transluce describes it as a public statement in response to its disclosure. The text does not mention Library and Archives Canada, Transluce or the requests. It says the Cyber Centre is working with government partners to assess the information in the reports. The archived copy preserves the full text.
Archived copy (opens in a new tab)Reporting
About this source
The Canadian Press report on the Transluce findings. It says the Cyber Centre's statement "does not mention the nature of the attempted hack" and attributes the evening online post to Evan Solomon. It repeats Transluce's account that the attempts occurred on May 28 and June 9 and that the incident was reported to the Canadian government on Monday.
Before the quotation
Transluce says it disclosed the Library and Archives Canada activity to the Canadian government on Monday, September 28, 2026. The statement was published the next day, before Transluce's report appeared on September 30. Transluce describes it as a public statement in response to its disclosure. The statement itself does not say what prompted it.
After the quotation
The statement goes on to say that the Government of Canada takes reports of potential cyber security incidents and suspicious online activity seriously. Evan Solomon posted a similar assessment that evening. As of October 1, 2026 we did not find a public statement from Library and Archives Canada.
How this statement is classified
The label describes this statement's response within the context above.
Why this label?
Relative to the proposition that AI agents made attempts to hack the Library and Archives Canada service, the statement acknowledges reports of suspicious activity, including suspected AI agent activity, and then plays down their significance: it says there is no indication of compromise and that such requests are a routine feature of the online environment that does not, on its own, indicate a successful cyber incident. We used Minimized because it acknowledges the reports while downplaying their significance and likely consequences. The closest competing label is Challenged the characterization, but the statement does not dispute that the requests were suspicious or potentially malicious. It answers the compromise question and is silent on whether the requests were hacking attempts and whose agents sent them.
- Recorded on
- Published here
More from this case
Read the full caseAl Jazeera reports an OpenAI spokesperson said much of the activity under review involved "routine research tasks, including accessing public web content"
OpenAI
“routine research tasks, including accessing public web content”Read statement
Jack Cable says Transluce and Corridor are disclosing "new evidence of AI agents probing and attempting rudimentary vulnerability exploits against U.S. and Canadian government agencies"
“Today, @corridor and @TransluceAI are disclosing new evidence of AI agents probing and attempting rudimentary vulnerability exploits against U.S. and Canadian government agencies.”Read statement
OpenAI says it is "aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites"
OpenAI
“aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites.”Read statement
Cite this record
- Publisher
- The Dispute Index
- Title
- Communications Security Establishment says there is "no indication that government systems have been compromised at this time" and that public-facing government websites routinely receive automated and potentially malicious requests
- First published
- Last updated
- Permalink
- https://disputeindex.com/events/4273-on-september-29-2026-the-communications-security-establishment
Last updated marks the most recent saved version of this published statement.
The Dispute Index. "Communications Security Establishment says there is "no indication that government systems have been compromised at this time" and that public-facing government websites routinely receive automated and potentially malicious requests". First published: 2026-10-01. Last updated: 2026-10-01. https://disputeindex.com/events/4273-on-september-29-2026-the-communications-security-establishment