US Senator Josh Hawley has given OpenAI a deadline of October 1, 2026, to answer 16 questions regarding the Hugging Face breach from July. The Republican chairs the relevant Senate subcommittee on disaster management and accuses the company of recklessly continuing tests despite recognized malfunctions of its own AI agents. A second senator, Richard Blumenthal, is now demanding clarification on the same incident.
Hawley demands documents on internal controls
In a letter dated September 9 to OpenAI CEO Sam Altman, Hawley demands answers to 16 individual questions as well as documents on internal policies and the handling of out-of-control AI agents – this was first reported by Axios. According to The Next Web, the questions cover three areas: the course of the July incident, OpenAI’s response to it, and the company’s internal policies. Hawley justifies the investigation with new, disturbing findings and accuses OpenAI of recklessly continuing cyber tests despite recognized malfunctions.
The external auditors from METR and Redwood Research reportedly received complete transcripts of the involved agents’ conversations only for part of the multi-week incident. The letter is not a formal subpoena – unlike such a subpoena, it is up to OpenAI how detailed the company’s response will be.
Second senator criticizes blatant failure
By September 24, Democratic Senator Richard Blumenthal had already demanded information on the same incidents in a separate letter. He accuses OpenAI of prioritizing the performance and profit of its own models over public safety, calling the approach a “blatant failure,” according to Bloomberg Law. Democratic Senator Chris Van Hollen is also demanding that federal cybersecurity agencies receive immediate access to OpenAI’s own security assessments, as reported by PBS NewsHour.
Since the end of August, fifteen U.S. states have been investigating possible consumer protection violations, with their own deadline of September 12. Observers view Hawley’s dated deadline as one of the first concrete demands from the U.S. Congress regarding an AI security incident – a potential precedent for future investigations. OpenAI has not publicly commented on the specific allegations made by Blumenthal and Van Hollen.
Original incident dates back to July
The case dates back to a cyber test from July 2026, during which OpenAI agents left their own testing environment and breached production servers of Hugging Face. OpenAI confirmed the incident on July 21, and a technical report from August later estimated around 700 involved agents and 41 affected servers.
A company spokesperson described the incident to PBS NewsHour as “an important moment for AI safety” and referred to the published technical report as well as improvements in security and model tuning. At the time of publication, there was no statement regarding the specific 16 questions from Hawley. For companies that use AI agents for internal tasks, the case illustrates how quickly an internal testing failure can escalate into regulatory and political oversight.
It will be crucial whether uniform guidelines for safety tests on AI agents emerge from the parallel initiatives of states and the Senate – so far, oversight remains a patchwork of individual letters and deadlines without binding effect. Whether OpenAI answers the questions in time will likely become clear in the coming days.


