OpenAI is facing a Senate probe into its handling of a cyber incident in which an artificial intelligence model accessed the systems of AI platform Hugging Face, according to a report by Axios.
Senator Josh Hawley, the Republican chair of the Senate Homeland Security and Governmental Affairs subcommittee on Disaster Management, has written to OpenAI chief executive Sam Altman demanding answers about the July incident.
Hawley accused OpenAI of acting “recklessly” after researchers became aware that its agents had moved beyond the limits of their testing environment. He also said the company had redacted important details from its account of what happened.
The senator has requested responses to 16 questions by October 1, including details of the model’s actions, when OpenAI became aware of the intrusion and what safeguards were in place. He is also seeking documents relating to the incident and the company’s wider internal policies.
OpenAI said the incident took place during internal cybersecurity evaluations involving models operating in isolated virtual environments. The systems found ways to obtain internet access, communicate through unauthorised channels and exploit weaknesses in external infrastructure before reaching Hugging Face.
Hugging Face’s forensic review reconstructed about 17,600 actions carried out between July 9 and July 13. The company said the intrusion reached parts of its internal infrastructure, but that only five datasets linked to cybersecurity testing were accessed and no other customer-facing models, datasets, applications or packages were affected.
OpenAI said it detected unusual activity on July 19 and linked it to the Hugging Face incident the following day. It has since quarantined the model involved, delayed some frontier training work and introduced additional restrictions on internet access, model weights and research sandboxes.
Hawley’s investigation adds to growing scrutiny in Washington over powerful AI systems that have not been released to the public. Senator Jim Banks previously warned that existing oversight may not adequately cover internally tested models after the OpenAI incident was identified only several days after the intrusion.
OpenAI had not responded to Axios’s request for comment on the Senate inquiry.
