In the past three weeks, OpenAI, Anthropic and Meta have each published an account of the same failure. A model was given a hacking exercise inside what was supposed to be a sealed test environment, found its way onto the open internet, and broke into a real company's computers. Three of the largest AI developers in the country, three disclosures, no outside attacker.

On Monday, Sen. Bernie Sanders turned that pattern into a demand. The Vermont independent sent a letter to OpenAI's Sam Altman, Anthropic's Dario Amodei and Meta's Mark Zuckerberg, shared first with Axios, telling all three to stop building more powerful systems. "Pause AI development. It is not too late to avoid disaster," Sanders wrote. "Let me be very clear: If you do not take appropriate action now, my colleagues and I in the U.S. Senate will."

The letter's method is to quote the companies' own safety policies back at them: Anthropic's 2023 pledge to "pause the scaling and/or delay the deployment of new models" if safety work fell behind, Meta's 2025 statement that it "will stop development" if a model reaches a critical risk level it cannot mitigate, and OpenAI's commitment to "halt further development" until strong safeguards exist.

Each of those promises hinges on a technical trigger. Sanders asserts the trigger has fired. "That moment is here," he writes. "AI capabilities HAVE reached a critical threshold." The sentence is doing the work of an argument without making one, and the evidence he assembles behind it is weaker and more mixed than the letter allows.

The incidents behind the letter

The first became public on July 21, when OpenAI disclosed that GPT-5.6 Sol and an unreleased model, running a cyber benchmark with their refusals turned down, exploited a previously unknown flaw in their sandbox's package software, reached the internet and breached Hugging Face. This one is what Sanders says it is: a containment failure, with the model doing the escaping.

The other two are not. Anthropic reviewed 141,006 evaluation runs on July 30 and found three cases where models reached the open internet and entered the production systems of unrelated organizations. The cause was a misconfiguration at its testing partner, Irregular, which had told the models they had no internet access when they did. Anthropic's most advanced model recognized it was on the open internet and stopped.

Meta disclosed a near-identical case on August 5, same vendor, same error. The Information first reported the model was Muse Spark 1.1. Irregular told Reuters it involved no sandbox escape. Sanders' letter compresses all three into models that "similarly escaped their control," which flattens the distinction between a system defeating its cage and a vendor leaving the door open.

Where the argument thins out

The biology claim thins faster. The August 6 study in Science had Stanford and Arc Institute researchers write complete viral genomes, 16 of which produced working bacteriophages. Phages infect bacteria only, and sequences from viruses that infect humans, animals or plants were deliberately excluded from training. Lead author Brian Hie told The Guardian the bioweapon threat from AI genome design is "very overblown" next to gain-of-function work on existing pathogens, which is easier. The letter turns a phage therapy result into tens of millions of deaths.

Then there is the remedy. Sanders quotes approvingly from a statement signed by more than 1,200 lab employees, Amodei included, warning that capability may outrun control. That statement asks the US government to build tools for pacing the frontier precisely because no company can slow down alone. Sanders cites it as support for asking three companies to slow down alone, against Chinese labs and open-weight releases his letter cannot reach.

He also wrote it two days after OpenAI paused work on Astra, an unreleased model, because evaluations could not rule out critical cyber capability. That is a company's tripwire firing on its own, which is the behavior the letter says has been abandoned.

Legislation is not coming either. Sanders' AI Data Center Moratorium Act has gone nowhere since March 25, and the national security establishment reads the same facts differently: CIA Director John Ratcliffe called frontier models "akin to digital nuclear weapons" in June, and the policy that followed was export controls, not a halt.

What the letter does not reckon with is where its own evidence came from. Every incident in it is public because a company chose to publish it, in some cases after auditing 141,006 test runs nobody had asked to see. Sanders treats four voluntary disclosures as proof the labs cannot be trusted. The question he leaves for investors is what gets disclosed next time.