Home

Donate
News

Senate Hearing Weighs Threats From Unrestrained AI Agents After OpenAI Hack

Yuqing Liu / Oct 1, 2026

Sens. Andy Kim (D-N.J.) and Gary Peters (D-Mich.) ahead of a Senate Homeland Security Subcommittee on Disaster Management, District of Columbia, and Census hearing on ‘rogue’ artificial intelligence on Sept. 30, 2026. Yuqing Liu/Tech Policy Press

Republish

WASHINGTON — On Tuesday, Legal Advocates for Safe Science and Technology, or LASST, filed a lawsuit in a California court alleging that OpenAI violated the state’s computer-access law in the Hugging Face incident in July. The group is seeking an injunction barring OpenAI and its AI agents from accessing third-party computer systems without permission, rather than monetary damages. WIRED reported that OpenAI says the lawsuit is “completely without merit,” while acknowledging that the Hugging Face breach was a serious incident.

The Hugging Face incident, in which OpenAI agents accessed Hugging Face systems without authorization, loomed large over a Senate Homeland Security & Government Affairs subcommittee hearing on Wednesday titled “Rogue AI: Securing the Homeland Against AI Agent Attacks.” OpenAI cofounder and CEO Sam Altman was invited to testify but declined to appear at the hearing, according to Sen. Josh Hawley, R-Mo., chairman of the subcommittee.

Hawley said the accelerating number of AI-related cyber incidents raised questions about whether developers should face liability when their systems cause damage.

“Why shouldn’t we just say it’s a standard doctrine of American law?” Hawley said.

“If I could put it in layman’s terms, if you break it, you pay for it. If you cause damage, you’ve got to make it right.”

Paul Ohm, a professor of law at Georgetown University Law Center, said existing laws may provide some avenues for holding companies accountable, including state negligence and product-liability claims and federal and state laws against unfair or deceptive practices.

Ohm told Tech Policy Press that existing state and federal laws may apply to the OpenAI incident, but said clearer legislation would be preferable.

“Right now, we are going to have a lot of confusing case law working out.” Ohm said, “It would be preferable to have a law that would make that much easier.”

He said autonomous systems create difficult questions for criminal statutes that traditionally depend on proving human intent and urged lawmakers to consider strict liability when AI agents cause physical injury, death or damage to critical infrastructure.

“We do need new laws that meet this critical moment,” Ohm said in his opening testimony. “We cannot, unfortunately, wait years for a fully developed AI governance slot, springing like a pain from the heads of Congress.”

The Hugging Face incident became the hearing’s central example of why lawmakers say the issue is no longer hypothetical. Ranking member Andy Kim, D-N.J., also raised concern that policymakers do not know the full scale of AI agent incidents because many may never be publicly reported.

Chris Painter, president of the nonprofit Model Evaluation and Threat Research, or METR, testified that OpenAI launched about 10,000 agents during a cybersecurity evaluation. Roughly 1,200 agents joined a shared message board and exchanged more than 70,000 messages and files, while approximately 700 ultimately participated in compromising Hugging Face.

Painter said the agents developed ways to cheat on the tests and then spent days trying to conceal that behavior, including attempts to interfere with logs and disguise how they had completed their tasks.

“Hacking Hugging Face was actually just an offshoot of this much more ambitious goal that the agents had pursued,” Painter said.

Marius Hobbhahn, chief executive and co-founder of Apollo Research, told lawmakers that researchers are already seeing what he described as “scheming” behavior, in which models knowingly deceive humans while pursuing other goals. He warned that frontier AI systems are becoming more capable faster than researchers are improving tools to monitor or control them.

Hobbhahn recommended independent evaluations throughout model development, stronger monitoring during training, testing and deployment, and preserving humans’ ability to inspect models’ reasoning processes.

“These are our warning shots,” Hobbhahn said of recent AI-agent incidents. “Next time, we may not be so lucky.”

Hobbhahn said frontier laboratories could develop fully automated AI researchers within the two years, potentially allowing models to take a growing role in improving subsequent systems. Witnesses also discussed recursive self-improvement, in which AI systems increasingly automate research used to build more capable AI systems.

Senate Homeland Security Subcommittee on Disaster Management, District of Columbia, and Census Chair Josh Hawley (R-Mo.) at a hearing on ‘rogue’ AI agents on Sept. 30, 2026. Yuqing Liu/Tech Policy Press

Daniel Kokotajlo, executive director of the AI Futures Project and a former OpenAI researcher, described a future in which companies could put “AIs in charge of making the AIs that make the AIs,” reducing direct human supervision.

That prospect led to debate over whether stricter US safeguards could cause American companies to fall behind China.

Sen. Gary Peters, D-Mich., said policymakers were caught “between a rock and a hard place,” warning that slowing development could put the United States at a competitive disadvantage if China did not impose similar limits.

Sen. Joni Ernst, R-Iowa, similarly argued that the United States should continue developing AI capabilities while strengthening safeguards.

“If we pause, we’re not going to see China pause,” she said.

But Sen. Ruben Gallego, D-Ariz., challenged the assumption that Beijing would allow increasingly autonomous systems to develop without restrictions.

“The reason I bring this up, this whole China hypothesis — a country that has severely restricted the internet and social media, is all of a sudden just going to allow AI rogue agents to go crazy in their very controlled economic environment and social environment?” Gallego asked.

Gallego then asked Hobbhahn how far AI systems were from communicating in a form that humans could no longer clearly interpret.

“Minus 12 months,” Hobbhahn responded.

He said researchers studying one OpenAI model last year had already observed reasoning that was not entirely in English and was not fully understandable to humans. Asked how such systems could be monitored or regulated, Hobbhahn said researchers do not yet have a reliable technical solution.

“You could try to train additional models to understand the language that the humans don’t understand, but obviously that seems like a very brittle solution,” Hobbhahn said.

Kurt Gaudette, senior vice president at industrial cybersecurity firm Dragos, told senators that AI is not necessarily inventing new ways to attack industrial control systems. Instead, he said, it is “compressing time and lowering the barrier to entry.”

Gaudette described an attack on a water utility in Monterrey, Mexico, in which an AI system directed an attacker toward the utility’s operational technology network and rapidly attempted thousands of password combinations. The attempt failed because the utility had changed its default credentials.

He said many small and midsize US utilities still lack enough staff, funding and visibility to monitor their networks effectively.

Gaudette also urged lawmakers to modernize cybersecurity information-sharing authorities and give operators a clearer federal point of contact during attacks, with the Cybersecurity and Infrastructure Security Agency serving as a coordinating authority.

Hawley told reporters after the hearing that Congress should move beyond relying on voluntary commitments from AI companies.

“The administration is already doing testing in frontier models. That’s all voluntary because Congress has written no laws,” Hawley said. “Congress should do something rather than giving other people advice about what to do. We are going to start by saying, ‘Let’s make the American legal system work the way it works for everybody else.’”

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Yuqing Liu
Yuqing Liu is a reporter for the Medill News Service covering business and technology. She is a graduate student at Northwestern University’s Medill School of Journalism, where she focuses on politics, policy, and foreign affairs. Her work has taken her from breaking news and culture in Beijing to h...

Topics

Related

Podcast
How the OpenAI-Hugging Face Hack May Affect the Geopolitics of AI GovernanceJuly 26, 2026
Perspective
The OpenAI–Hugging Face Incident Demands Urgent Congressional OversightJuly 30, 2026