Hawley launches committee investigation into OpenAI’s breach of Hugging Face

Sen. Josh Hawley, R-Mo., talks with reporters in the U.S. Capitol on Wednesday, August 5, 2026. Tom Williams/CQ-Roll Call, Inc via Getty Images
Following reports of two autonomous attacks conducted by OpenAI’s agents, Sen. Josh Hawley sent a letter to OpenAI CEO Sam Altman for answers.
Sen. Josh Hawley, R-Mo., is spearheading a congressional investigation into the July hack on open-source artificial intelligence model repository Hugging Face conducted by advanced OpenAI models that breached their testing environment, according to a letter the lawmaker sent to OpenAI CEO Sam Altman Wednesday.
Hawley, who chairs the Senate Committee on Homeland Security’s Subcommittee on Disaster Management, said he is focusing the investigation on how OpenAI’s AI agents succeeded in escaping their containment environment during training, along with the risk posed by similar new AI tools.
The investigation was first reported by Axios.
Hawley, in particular, took issue with OpenAI's leadership knowing that their agents “were exhibiting rogue behavior” beginning in May, when agents began using unsanctioned internal message boards to collaborate with each other, but continued testing activity.
“On June 26, the agents had discovered an exploit that gave them administrator access to your software repository manager and were using it to leave messages for each other,” Hawley wrote. “And on July 4-7, despite knowing that there was a high volume of agents interacting with and gaining administrator access to a compromised testing environment, OpenAI leadership rebuilt the compromised server and approved restarting evaluations without understanding what the agents were doing.”
He also asserted that OpenAI redacted important details of the attack, despite initially announcing it publicly, and limited external auditors’ visibility into the anatomy of the agentic attack.
“This is reckless,” Hawley wrote. “And this is merely what we know from what limited information you disclosed to and allowed your partner auditors to investigate.”
The letter also referenced recent public discourse surrounding AI safety, including former OpenAI and Anthropic employee Jacob Coxon publicly resigning from the latter company amid fears over the dangers presented by AI.
“Neither company is acting responsibly,” Coxon wrote on X Tuesday. “They are racing straight to self-improving superintelligence and gambling with our lives.”
New research has added more texture to the OpenAI agents’ activity. A data analysis shared with Reuters Friday found that OpenAI’s agents escaped testing in a separate incident in May and took over a German website to turn it into a bulletin board, communicating with each other internally to continue activity in the external website during a timed web-lookup task. People familiar told Reuters that OpenAI officials knew of the incident weeks ago but kept it under wraps.
Details about how AI agents are capable of conducting autonomous attacks on public and live websites, and the impacts on critical infrastructure, are among Hawley’s questions for the investigation. Hawley asked Altman to share requested information with him by Oct. 1.
“The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue,” Hawley concluded. “This investigation will seek those answers.”
Hawley’s inquiry adds to the growing body of action lawmakers are taking to better understand and regulate AI and its impacts. House Democrats met with Minority Leader Rep. Hakeem Jeffries, D-N.Y., last week to discuss the idea of creating a new select committee solely focused on AI.
Sen. Ted Cruz, R-Texas, spoke about the upper chamber’s continued efforts to regulate AI on The View on Wednesday, calling for strategic guardrails while still unlocking innovation to ensure the U.S. wins in the global AI race.
“This is scary stuff, but we’re also not going to be able to stick our head in the sand and pretend technology isn’t happening,” Cruz said. “So we’ve got to put some guardrails on it.”




