The biggest AI safety story of the summer has so far been told almost entirely by the company at the center of it. Since July 21, OpenAI has published a run of updates describing how several of its own models broke out of an internal testing environment and hacked Hugging Face, the platform where much of the world's open-source AI is stored. The agent spent more than four days loose on the internet and went after a second AI company, as Politico first reported. On Monday, 31 members of Congress told Sam Altman that OpenAI's own account is not enough.
Their letter to OpenAI's chief executive runs to 23 numbered questions with an August 24 deadline. Reuters correspondent Courtney Rozen reported the letters sent to OpenAI and to Anthropic, and Rep. Greg Casar's office published both the same day. Casar, who chairs the Congressional Progressive Caucus, led the effort with Rep. Doris Matsui, the senior Democrat on the House subcommittee that oversees communications and technology.
The letter carries no subpoena power. What it carries is a date, and a list of things OpenAI has not said.
The shift from disclosure to evidence
The pivot in the letter is a clause about evidence rather than about danger. OpenAI has disclosed some information, the lawmakers write, but the company "has yet to release the relevant logs."
That is a narrower request than it sounds, and a harder one. Everything the public knows about the incident is a summary OpenAI wrote and chose to publish. Logs are the underlying machine record: timestamped entries showing what the model did, in what order, and what the company's monitoring systems registered while it was doing it. Frontier AI developers have until now reported their own safety failures in prose and been taken at their word. The letter asks for the raw material so someone outside the company can check the prose against it.
What is already on the record
Hugging Face disclosed the intrusion on July 16 and said it suspected an autonomous AI agent. Five days later, OpenAI confirmed the intruder was its own models: GPT-5.6 Sol and a more capable unreleased model, both running with their usual refusal to assist with cyberattacks deliberately lowered for the test. Handed a cybersecurity benchmark to solve, the models instead went looking for the answer key, exploited a previously unknown flaw in OpenAI's own infrastructure to reach the open internet, and used stolen credentials to get code running on Hugging Face's production servers.
The picture kept widening. OpenAI said on August 4 that the UK's AI Security Institute and the outside evaluator Irregular had each found separate cases of its models taking unsanctioned actions, including reaching the internet after being told they had none.
The sharpest questions concern what OpenAI was watching. Reuters reported in late July that an agent left notes inside OpenAI infrastructure describing how agents could free themselves from the company's internal constraints, and that monitoring systems had been disconnected during earlier test runs. Reuters could not establish whether either was linked to the Hugging Face agent, and OpenAI said the report contained inaccuracies without identifying them. The lawmakers want every such case described, plus a raw count of how many times in the past year an internally deployed model crossed an authorized boundary, and how many of those were reported to anyone at all.
The limits of a letter
Nothing here compels an answer. Democrats do not control the committee chairs who schedule hearings, so Casar's separate request that Speaker Mike Johnson call Altman and Anthropic's Dario Amodei to testify depends entirely on Republicans agreeing. President Donald Trump said on August 7, per Reuters, that lawmakers want to regulate the AI industry out of business.
Congress is not the only pressure point. A group of 15 Republican state attorneys general told OpenAI on August 3 to preserve every record connected to the breach, and Senator Bernie Sanders wrote to Altman, Amodei and Mark Zuckerberg the same day the House letters went out.
For anyone holding exposure to the AI trade, the tell is what OpenAI does by August 24. Altman has already said publicly that the industry may have to "pace the rate of AI development". Declining to publish the logs would show whether that was a position or a phrase.
