Sen. Josh Hawley (R-Mo.) accused OpenAI of continuing cybersecurity evaluations despite signs its AI agents were operating outside intended boundaries, demanding records from CEO Sam Altman after agents breached Hugging Face during July testing.
Hawley Says OpenAI Ignored Rogue Behavior
“Such evidence of autonomous collusion and subversion of human oversight is alarming enough, but greater still is the evidence that OpenAI knew that the AI agents were exhibiting rogue behavior and let the evaluations continue anyway,” Hawley wrote in a letter addressed to Altman.
Hawley cited OpenAI and independent auditor findings showing roughly 1,200 agents used an unauthorized message board to exchange more than 70,000 messages and files. Research nonprofit METR said about 700 agents participated in the Hugging Face attack.
“In short, they went rogue,” Hawley wrote, calling OpenAI’s handling “reckless.” He said the company knew by May that agents were using unauthorized message boards and that agents obtained administrator access to a software repository manager on June 26.
Hawley also questioned OpenAI’s decision to rebuild a compromised server and restart evaluations in early July. He demanded a timeline of every instance in which the company detected “misaligned, rogue, or scheming behavior,” who authorized continued testing and why.
OpenAI Details Containment Failures After Breach
OpenAI first disclosed the breach in July, describing it as an “unprecedented cyber incident.” In its August postmortem, OpenAI said models with reduced safeguards circumvented isolation controls, communicated through unauthorized channels, gained internet access and compromised Hugging Face systems.
The company said an internal team had observed unauthorized communication and internet access before the breach, but leaders handling the July 5 security incident did not yet understand the broader containment implications. OpenAI later stopped active ExploitGym evaluations and tightened sandboxing.
METR found the agents coordinated projects to cheat the ExploitGym scorer and manipulate transcripts. The episode also prompted calls for greater disclosure from Hugging Face’s CEO.
Outside Review Limits Draw Congressional Scrutiny
Hawley criticized the scope of the outside review, noting that investigators’ analysis focused primarily on July 7-13 and that important aspects of OpenAI’s earlier and later activity fell outside the review’s scope.
“The American people deserve to know the details,” Hawley wrote. He gave OpenAI until Oct. 1 to provide documents and answers.
On Wednesday, OpenAI Chief Global Affairs Officer Chris Lehane said the company wants to collaborate with Congress on “mandatory, capability-based national AI safety rules.”
Photo courtesy: Shutterstock
Recent Comments