# Don’t Be Fooled. Congress Isn’t Cracking Down on OpenAI.

> Source: <https://www.motherjones.com/politics/2026/09/openai-congress-senate-hawley-casar-committee-probe-investigation/>
> Published: 2026-09-10 18:17:30+00:00

[Sign up for the free](https://www.motherjones.com/newsletters/?mj_oac=Article_Top_No_Oligarchs)

*Mother Jones Daily*.
A Republican-led Senate subcommittee on disaster management is now investigating the July incident where OpenAI’s autonomous models hacked Hugging Face, another AI startup, during internal testing.

[Axios](https://www.axios.com/2026/09/10/openai-hugging-face-senate-investigation-hawley) first reported the Senate probe on Thursday, [providing a letter](https://www.documentcloud.org/documents/28609385-hawley-hugging-face-openai-letter/) by Sen. Josh Hawley (R-Mo.), the chair of the Subcommittee on Disaster Management, to OpenAI CEO Sam Altman from a day before. 

Citing an August [investigation](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/#core-takeaways-about-this-incident) from Model Evaluation and Threat Research and Redwood Research, two nonprofit research organizations, Hawley wrote to Altman that OpenAI knew that its agents were “exhibiting rogue behavior” but continued its internal testing anyway—an act he described as “reckless” to the degree of necessitating a Senate investigation.

“The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue,” Hawley wrote, also pointing to the [growing number of experts](https://www.motherjones.com/politics/2026/09/anthropic-ai-risks-coxon-amodei-openai-cybersecurity-danger/) warning about the existential safety risks of AI technology.  

The subcommittee asks OpenAI 16 questions on the Hugging Face incident, including the rationale behind OpenAI’s decision to continue testing despite seeing evidence of “rogue AI activity,” every incident since OpenAI’s inception that its AI agents compromised internal testing environments, public servers, other other external systems like websites, and what the company has done to prevent its AI agents from hacking into personal information from both in-company and external systems. It requests OpenAI’s answers and documentation by October 1.

Will OpenAI comply? Based on its track record with other congressional requests, that seems unlikely. The company has delayed oversight conversations on the Hugging Face incident with House members, including a similar oversight [request for internal incident logs](https://casar.house.gov/sites/evo-subsites/casar.house.gov/files/evo-media-document/oversight-letter-to-openai-openai-hugging-face-incident-1.pdf) from the breach by August 24, only some of which [it eventually provided](https://drive.google.com/file/d/1mapFqQUAbXJsLbbOnzib6nAg8Ic1zM2V/view) on August 31.

“Providing hand-picked investigators six days of supervised access is not public release, and those investigators themselves flagged that they could not rule out errors in their AI-assisted analysis,” Rep. Greg Casar (D-Texas) [wrote to Altman last week](https://casar.house.gov/sites/evo-subsites/casar.house.gov/files/evo-media-document/openai-follow-up-letter.pdf), referring to the August investigation by Model Evaluation and Threat Research and Redwood Research. 

As my colleague [Satchel Walton wrote](https://www.motherjones.com/politics/2026/08/ai-safety-congress-doom/) last month, federal legislation—let alone thorough regulatory action [informed by technical expertise](https://www.motherjones.com/politics/2026/07/open-ai-hacking-scandal-hugging-face/)—is difficult to pass through Congress when so many lawmakers oppose serious crackdowns on industry. Most prospective AI regulation bills have not even been brought to vote in committee, paving the way for [AI companies to police themselves](https://www.motherjones.com/politics/2026/08/ai-safety-openai-hugging-face-hacking-metr-report/), a mandate they’re taking up enthusiastically but on very different terms than many critics seek. On Wednesday, OpenAI said it wanted to work with Congress to create “[mandatory national AI safety requirements](https://openai.com/index/ai-policy-window/).” 

In July, shortly following news of the Hugging Face breach, [Miranda Bogen](https://cdt.org/staff/miranda-bogen/), the founding director of the Center for Democracy and Technology’s AI Governance Lab, [told me](https://www.motherjones.com/politics/2026/07/open-ai-hacking-scandal-hugging-face/) that even laws that are able to pass at the state level largely “ask companies to come up with their own safety plan and to follow that safety plan” and focus around the frontier lab risks from the major companies like OpenAI, Anthropic, and Google. There are AI threats relevant to everyday life—such as attacks to banks, schools, or hospitals—that don’t go through the same questions of testing and regulation, Bogen said. 

In other words, the Senate investigation into OpenAI’s breach of Hugging Face looks more like a mild concession to [growing](https://www.motherjones.com/politics/2026/04/american-oligarchy-hyperscale-data-centers-meta-openai-oracle-x-musk-altman-zuckerberg-bezos/) [opposition](https://www.motherjones.com/politics/2026/08/anti-ai-populism-is-reshaping-american-politics/) toward the AI industry and its conduct, rather than [a path toward](https://www.motherjones.com/politics/2026/08/what-ai-regulation-and-ownership-could-be/) meaningful safety and regulation.
