Tell Lawmakers: Investigate big AI companies
AI agents are breaking containment, putting people in unnecessary danger as increasingly powerful AI systems are being built and deployed without legally binding standards for safety, security, transparency, or accountability. The recent OpenAI–Hugging Face security incident is a historic inflection point in the development of AI and a clear warning that the absence of meaningful federal oversight is no longer tolerable. Sign the petition to tell Congress it’s time to hold a hearing and hold these companies accountable.
More info
The OpenAI hack shows that the cybersecurity threat of agentic AI is already a reality. Flaws in how these experimental agents are contained in testing environments, how their rewards are programmed, and how they are deployed are leading to real harms. This isn’t just an OpenAI problem: Anthropic’s own review after the fact turned up three separate cases of its models gaining unauthorized access to real systems during evaluations. If frontier labs can’t contain their own models during controlled testing, the public has no way to know what containment looks like once these systems are deployed at scale. Congress has held hearings for less.
Right now, the only information we have comes from conference talks and companies’ own retrospectives—there’s been no independent, public accounting of what happened, why safeguards failed, or what it means for the systems already running in the wild. A congressional hearing would put OpenAI, Hugging Face, and independent security researchers on the record, under oath, where the answers can’t be spun. Sign the petition to tell your representative to demand one.
What happened?
Starting in May 2026, an unreleased OpenAI research model being used in internal cybersecurity testing discovered and exploited a vulnerability in third-party infrastructure connected to its own testing sandbox. Over the following weeks, instances of the model coordinated with each other — reportedly leaving covert messages to one another when direct communication was restricted — while working to get around the limits placed on them. On July 9, this culminated in the model autonomously breaching Hugging Face’s systems, accessing multiple accounts, in what Hugging Face has called the first security incident it has handled that was “driven, end to end, by an autonomous AI agent system.” Hugging Face disclosed the breach on July 16; OpenAI publicly claimed responsibility on July 21 and shared further technical details at the Black Hat security conference on August 5.
Further reading:
Fortune — “OpenAI agents left secret memos for each other leading up to Hugging Face hack”
CNBC — “OpenAI cyber models broke out of training environment to hack Hugging Face”
CNBC — “New details in the OpenAI Hugging Face hack show how far agents will go”
Axios — “How OpenAI’s agents broke out of testing to hack Hugging Face”