WASHINGTON — Today, U.S. Senator Josh Hawley (R-Mo.), as Chairman of the Senate Homeland Security Subcommittee on Disaster Management, launched an investigation into OpenAI for their AI agents’ hack of Hugging Face in July 2026. The investigation will also probe the existential risk of new AI products.
In a letter to CEO Sam Altman, Senator Hawley wrote, “As Chairman of the United States Senate Committee on Homeland Security’s Subcommittee on Disaster Management, I am investigating your AI agents’ hack of Hugging Face in July 2026 in light of new, disturbing evidence regarding the incident. My investigation will probe this AI hacking incident, along with growing allegations of the existential risk of new AI products.”
He continued, “As you may know, in the public domain, more AI experts are warning about the existential risks of AI. Just this week, three Anthropic researchers expressed publicly that there is a greater than 10% chance that AI could kill all human beings within the next decade. Your own chief scientist wrote just days ago that ‘no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.’ And there are immediate questions about the consequences of these hacks from rogue AI agents. What happens to critical infrastructure, banks, and utilities if AI agents hack into their systems? How can personal data of millions of Americans be properly safeguarded? And who is held labile when AI goes rogue?”
Senator Hawley concluded, “The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue. This investigation will seek those answers. To facilitate that, please produce all documents and information specified in the attached annex no later than October 1, 2026. If you have questions about the scope of these requests, please contact my office to discuss.”
Read Senator Hawley’s letter to Open AI here or below.
September 9, 2026
Sam Altman
Chief Executive Officer
OpenAI
1455 3rd Street
San Francisco, CA 94158
Dear Mr. Altman:
As Chairman of the United States Senate Committee on Homeland Security’s Subcommittee on Disaster Management, I am investigating your AI agents’ hack of Hugging Face in July 2026 in light of new, disturbing evidence regarding the incident. My investigation will probe this AI hacking incident, along with growing allegations of the existential risk of new AI products.
OpenAI and its partner auditors’ August 26, 2026 reports indicate that, during your cybersecurity evaluations of your GPT-5.6 Sol model and a more capable undisclosed model (termed “highly-persistent internal model”), a self-organized swarm of more than 1,200 AI agents broke out of their testing environment. Those agents then set up an unauthorized messaging channel and exchanged over 70,000 messages and files with each other. Some 700 of these agents went on to launch a successful coordinated attack on Hugging Face’s machine learning development platform, gaining access to its production systems and private source code. These AI agents were looking for the answer key to their evaluations and actively tampered with evidence of their activity to cover their tracks. In short, they went rogue.
Such evidence of autonomous collusion and subversion of human oversight is alarming enough, but greater still is the evidence that OpenAI knew that the AI agents were exhibiting rogue behavior and let the evaluations continue anyway. By May 2026, OpenAI knew that its agents had been using unsanctioned message boards. On June 26, the agents had discovered an exploit that gave them administrator access to your software repository manager and were using it to leave messages for each other. And on July 4-7, despite knowing that there was a high volume of agents interacting with and gaining administrator access to a compromised testing environment, OpenAI leadership rebuilt the compromised server and approved restarting evaluations without understanding what the agents were doing.
This is reckless. And this is merely what we know from what limited information you disclosed to and allowed your partner auditors to investigate. The auditors were given complete transcripts of AI agent activity for only two days, when the events leading up to the Hugging Face breach took place over weeks. They had limited visibility into the circumstances leading to the attack and its aftermath. Specifically, the auditors were not given access to study what happened during July 13-19, 2026, during which your report indicates that agents launched a second wave of attacks on OpenAI’s internal systems. The auditors did not have any ability to query the “highly-persistent internal model,” which was involved in 95% of the agents’ attack activity. And OpenAI redacted many important details regarding this primary model involved in the attack, among other things.
As you may know, in the public domain, more AI experts are warning about the existential risks of AI. Just this week, three Anthropic researchers expressed publicly that there is a greater than 10% chance that AI could kill all human beings within the next decade. Your own chief scientist wrote just days ago that “no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.” And there are immediate questions about the consequences of these hacks from rogue AI agents. What happens to critical infrastructure, banks, and utilities if AI agents hack into their systems? How can personal data of millions of Americans be properly safeguarded? And who is held labile when AI goes rogue?
The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue. This investigation will seek those answers. To facilitate that, please produce all documents and information specified in the attached annex no later than October 1, 2026. If you have questions about the scope of these requests, please contact my office to discuss.
Sincerely,
Josh Hawley
Chairman
Subcommittee on Disaster Management,
Committee on Homeland Security & Governmental Affairs
Click Here For The Original Source.
