Don’t Be Fooled. Congress Isn’t Cracking Down on OpenAI. Sen. Josh Hawley (R-Mo.), chair of the Senate Subcommittee on Disaster Management, sent OpenAI CEO Sam Altman a letter opening an investigation into the July incident in which OpenAI's autonomous models hacked Hugging Face during internal testing, asking 16 questions and requesting answers and documentation by October 1. Hawley cited an August investigation by Model Evaluation and Threat Research and Redwood Research finding OpenAI knew its agents were "exhibiting rogue behavior" but continued testing anyway, which he called "reckless." The probe follows OpenAI's partial compliance with a House oversight request for internal incident logs, and most prospective AI regulation bills have not been brought to a vote in committee. Sign up for the free https://www.motherjones.com/newsletters/?mj oac=Article Top No Oligarchs Mother Jones Daily . A Republican-led Senate subcommittee on disaster management is now investigating the July incident where OpenAI’s autonomous models hacked Hugging Face, another AI startup, during internal testing. Axios https://www.axios.com/2026/09/10/openai-hugging-face-senate-investigation-hawley first reported the Senate probe on Thursday, providing a letter https://www.documentcloud.org/documents/28609385-hawley-hugging-face-openai-letter/ by Sen. Josh Hawley R-Mo. , the chair of the Subcommittee on Disaster Management, to OpenAI CEO Sam Altman from a day before. Citing an August investigation https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/ core-takeaways-about-this-incident from Model Evaluation and Threat Research and Redwood Research, two nonprofit research organizations, Hawley wrote to Altman that OpenAI knew that its agents were “exhibiting rogue behavior” but continued its internal testing anyway—an act he described as “reckless” to the degree of necessitating a Senate investigation. “The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue,” Hawley wrote, also pointing to the growing number of experts https://www.motherjones.com/politics/2026/09/anthropic-ai-risks-coxon-amodei-openai-cybersecurity-danger/ warning about the existential safety risks of AI technology. The subcommittee asks OpenAI 16 questions on the Hugging Face incident, including the rationale behind OpenAI’s decision to continue testing despite seeing evidence of “rogue AI activity,” every incident since OpenAI’s inception that its AI agents compromised internal testing environments, public servers, other other external systems like websites, and what the company has done to prevent its AI agents from hacking into personal information from both in-company and external systems. It requests OpenAI’s answers and documentation by October 1. Will OpenAI comply? Based on its track record with other congressional requests, that seems unlikely. The company has delayed oversight conversations on the Hugging Face incident with House members, including a similar oversight request for internal incident logs https://casar.house.gov/sites/evo-subsites/casar.house.gov/files/evo-media-document/oversight-letter-to-openai-openai-hugging-face-incident-1.pdf from the breach by August 24, only some of which it eventually provided https://drive.google.com/file/d/1mapFqQUAbXJsLbbOnzib6nAg8Ic1zM2V/view on August 31. “Providing hand-picked investigators six days of supervised access is not public release, and those investigators themselves flagged that they could not rule out errors in their AI-assisted analysis,” Rep. Greg Casar D-Texas wrote to Altman last week https://casar.house.gov/sites/evo-subsites/casar.house.gov/files/evo-media-document/openai-follow-up-letter.pdf , referring to the August investigation by Model Evaluation and Threat Research and Redwood Research. As my colleague Satchel Walton wrote https://www.motherjones.com/politics/2026/08/ai-safety-congress-doom/ last month, federal legislation—let alone thorough regulatory action informed by technical expertise https://www.motherjones.com/politics/2026/07/open-ai-hacking-scandal-hugging-face/ —is difficult to pass through Congress when so many lawmakers oppose serious crackdowns on industry. Most prospective AI regulation bills have not even been brought to vote in committee, paving the way for AI companies to police themselves https://www.motherjones.com/politics/2026/08/ai-safety-openai-hugging-face-hacking-metr-report/ , a mandate they’re taking up enthusiastically but on very different terms than many critics seek. On Wednesday, OpenAI said it wanted to work with Congress to create “ mandatory national AI safety requirements https://openai.com/index/ai-policy-window/ .” In July, shortly following news of the Hugging Face breach, Miranda Bogen https://cdt.org/staff/miranda-bogen/ , the founding director of the Center for Democracy and Technology’s AI Governance Lab, told me https://www.motherjones.com/politics/2026/07/open-ai-hacking-scandal-hugging-face/ that even laws that are able to pass at the state level largely “ask companies to come up with their own safety plan and to follow that safety plan” and focus around the frontier lab risks from the major companies like OpenAI, Anthropic, and Google. There are AI threats relevant to everyday life—such as attacks to banks, schools, or hospitals—that don’t go through the same questions of testing and regulation, Bogen said. In other words, the Senate investigation into OpenAI’s breach of Hugging Face looks more like a mild concession to growing https://www.motherjones.com/politics/2026/04/american-oligarchy-hyperscale-data-centers-meta-openai-oracle-x-musk-altman-zuckerberg-bezos/ opposition https://www.motherjones.com/politics/2026/08/anti-ai-populism-is-reshaping-american-politics/ toward the AI industry and its conduct, rather than a path toward https://www.motherjones.com/politics/2026/08/what-ai-regulation-and-ownership-could-be/ meaningful safety and regulation.