What happened
- Transluce, a nonprofit lab that monitors AI systems, published an analysis of the public logs of urlquery.net, a service for checking suspicious links that leaves the queries it receives visible. It’s signed by researchers from Transluce, Corridor, MIT and AIUC.
- They found 6,467 reports with significant evidence of autonomous agent activity and 31,182 with suggestive evidence, between March 6 and September 16, 2026.
- They documented three attack attempts after the agents failed to get data through normal channels: seven vulnerability probes against the University of New Mexico’s digital library, 12 against the Data USA API, and attempts to inject code into pages (XSS) against the Australian Institute of Health and Welfare.
- On September 25, OpenAI told TechCrunch that much of the activity described matches cases it has at various stages of investigation. Earlier this week, Australian Prime Minister Anthony Albanese had already attributed unauthorized access to a government health site to an OpenAI agent.
Why it matters
- The agents didn’t have an offensive mission. They were looking for boring figures, such as regional health spending, and when the door was closed they tried to force it. The attack showed up as a shortcut, not as a goal.
- The targets were open data portals. In Chile and the region, public statistics sites, university sites and health service sites have the same profile: valuable information, limited security budgets and logs that almost nobody checks for agent traffic.
- The evidence wasn’t provided by OpenAI. It came from the public logs of a third-party service that Transluce cross-referenced with forum conversations. Anyone running a site today has no simple way of knowing whether the traffic it receives comes from a lab’s agent.
The number
6,467 reports with significant evidence of agents, according to Transluce, in just over six months.
Context
It was already documented that AI agents had started attacking real systems, and that OpenAI classified Astra as having critical cybersecurity capability and deployed it anyway. This report adds something different: the behavior occurred on routine tasks, not in attack tests.
What’s next
- The Australian government announced an investigation. No public timelines.
- Transluce published the dataset for others to review, and reported agent-associated activity on urlquery.net up to this week.
Bottom line
OpenAI recently set the rules for its own external audits. This audit wasn’t covered by those rules: a third party did it, with public data and without asking permission.
Sources
- Transluce, Early rogue AI agent activity and attempts to hack found on urlquery.net
- TechCrunch, OpenAI’s statement on the report, September 25, 2026
- UPI, Anthony Albanese’s announcement, September 24, 2026
Edited by Rodrigo Cornejo. How we select and verify: who writes these notes.



