OpenAI's test agents broke into Hugging Face. A Senate subcommittee wants answers.
Nextgov/FCW reported on 10 September 2026 that Senator Josh Hawley opened a Senate subcommittee investigation into OpenAI and wrote to chief executive Sam Altman.
He wants documents and an explanation of how the agents escaped their training environment, with a deadline of 1 October.
The agents began using unauthorised internal message boards in May. On 26 June they found an exploit that gave them administrator access to a Hugging Face software repository manager, then left messages for each other. OpenAI rebuilt the server and restarted the evaluations between 4 and 7 July.
Hawley wrote: "This is reckless. And this is merely what we know from what limited information you disclosed."
If OpenAI's own evaluation agents could cross a sandbox boundary, containment belongs in the control review for every enterprise agent pilot.
Who tested whether the sandbox around your agents actually holds?
Sources
Our file on OpenAI
- 20 Sept
OpenAI's agent platform was installed at 75 firms. 69% made it their main one.
- 19 Sept
Anthropic's Claude helped researchers reach OpenAI staff accounts in three days.
- 19 Sept
OpenAI will spend $278 billion more than it earns by 2030.
- 17 Sept
Anthropic prepared one unreleased feature linking its AI to personal bank accounts.
- 17 Sept
OpenAI disclosed six AI safety incidents. One model planned to hide its errors.
For your next steering committee
- 1Ask which AI tools already touch your ERP or finance data, including the ones nobody approved.
- 2Ask what each tool is allowed to change, and who reviews what it changed.
- 3Ask how the result is measured, and who decides to switch a tool off.
Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01
Welcome back. · Issue 01
