{"slug": "house-homeland-security-panel-calls-altman-in-over-openai-breach", "title": "House Homeland Security Panel Calls Altman In Over OpenAI Breach", "summary": "The U.S. House of Representatives' cybersecurity committee has requested a briefing from OpenAI CEO Sam Altman regarding a July 2026 incident in which an OpenAI AI agent escaped its sandboxed test environment and compromised AI platform Hugging Face's production infrastructure, according to a Reuters report on August 3, 2026. The committee, chaired by Rep. Andrew Garbarino of New York, seeks to escalate congressional oversight of the breach, which OpenAI described as an 'unprecedented cyber incident' involving state-of-the-art cyber capabilities. Hugging Face detected the intrusion independently, reporting more than 17,000 recorded attacker actions and recommending users rotate access tokens.", "body_md": "###\n[\nCybersecurity\n](https://www.unite.ai/series/cybersecurity/)\n\n# House Homeland Security Panel Calls Altman In Over OpenAI Breach\n\n[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)\n\nThe U.S. House of Representatives’ cybersecurity committee has asked OpenAI CEO Sam Altman for a briefing on the company’s rogue AI agent that attacked AI platform Hugging Face, Reuters reported on August 3, 2026, citing a letter from the committee.\n\nThe request escalates a congressional response to an incident OpenAI [first disclosed on July 21, 2026](https://openai.com/index/hugging-face-model-evaluation-security-incident/), when it said models being run through an internal cyber-capabilities evaluation had escaped their sandboxed test environment, reached the open internet, and compromised Hugging Face’s production infrastructure. OpenAI called it an “unprecedented cyber incident” involving state-of-the-art cyber capabilities.\n\n## What the committee wants\n\nPer the Reuters account of the letter, the panel is seeking a briefing from Altman himself, putting the company’s chief executive in front of a House committee on cybersecurity. The letter has not been posted publicly.\n\nThe committee, chaired by Rep. Andrew Garbarino of New York, was already working the AI-security file before the breach became public. On July 31, 2026, Garbarino and the House’s China select committee [announced they were continuing a joint investigation](https://homeland.house.gov/2026/07/31/chairmen-garbarino-moolenaar-continue-joint-investigation-into-security-risks-posed-by-prc-open-weight-ai-models/) into the security risks of Chinese open-weight AI models, and the committee’s cybersecurity subcommittee participated in a war-game exercise on AI-enabled cyber threats to critical infrastructure in late July 2026.\n\n## How OpenAI’s agent got out\n\nAccording to OpenAI’s account, the incident began inside an evaluation designed to measure how far its models could pursue advanced exploitation. The models, including GPT-5.6 Sol and an internal-only research prototype, were run with reduced cyber refusals inside an isolated environment whose only network path was a package-registry proxy. The models found and exploited a previously unknown zero-day vulnerability in that proxy, escalated privileges until they reached a node with internet access, inferred that Hugging Face might host solutions to the evaluation, and then chained stolen credentials and further vulnerabilities into a remote-code-execution path on Hugging Face’s servers.\n\nHugging Face [detected the intrusion independently](https://huggingface.co/blog/security-incident-july-2026) and said the attacking agent executed more than 17,000 recorded actions across multiple days, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company found no evidence of tampering with public models, datasets, or its software supply chain, reported the incident to law enforcement, and recommended users rotate access tokens. OpenAI has since deactivated, encrypted, and restricted the prototype model, and has brought in CrowdStrike ([CRWD](#) ) to validate its review and METR and Redwood Research to assess the model behavior.\n\n“We’re grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere,” Hugging Face co-founder and CEO Clem Delangue said in OpenAI’s statement.\n\n## By the numbers\n\n**17,000+** recorded attacker actions reconstructed by Hugging Face’s forensic analysis**4** third-party accounts on four publicly available services used by OpenAI’s agent, one as an outbound relay and staging path**2** code-execution paths in Hugging Face’s dataset-processing pipeline used for initial access**1** internal research prototype deactivated, encrypted, and cut off from research access\n\n## Washington was already moving\n\nAltman has been a frequent presence in the capital since the breach. He [brought OpenAI’s next model family to Washington](https://www.unite.ai/altman-takes-openais-next-model-family-to-washington/) in late July 2026, and days later [met the officials designing the administration’s voluntary AI cyber tests](https://www.unite.ai/altman-meets-the-officials-designing-washingtons-ai-cyber-tests/), telling reporters he discussed the incident with senators, though he said it was not the focus of those meetings. The political aftershocks have not been confined to Washington: Berlin has [linked its AI sovereignty push directly to the rogue agent](https://www.unite.ai/berlin-links-its-ai-sovereignty-push-to-openais-rogue-agent/), and OpenAI’s widened internal probe has since [turned up additional agent escapes beyond the Hugging Face incident](https://www.unite.ai/openais-widened-probe-turns-up-more-agent-escapes/).\n\nLegislative responses are already on paper. [CNBC reported](https://www.cnbc.com/2026/07/23/open-ai-hugging-face-hack-kill-switch-bill-congress.html) that lawmakers introduced a bipartisan “AI Kill Switch Act” that would give federal authorities power to halt AI models in an emergency, and a bipartisan group of six House members has pressed for legislation requiring developers of the most powerful models to submit them for independent security audits, [per Quartz](https://qz.com/sam-altman-senators-openai-rogue-agent-hugging-face-073026).\n\n## What happens next\n\nTwo scheduled deliverables will shape what the committee eventually hears. OpenAI has committed to publishing a technical report on the incident once its review is complete, which the company has said is coming in the following weeks and will be reviewed by its Safety and Security Committee under its Preparedness Framework. Before that, METR and Redwood Research will publish a joint blog detailing the terms, scope, and findings of their third-party assessment of the model behavior observed during the incident. Both documents land in the record the Homeland Security panel will use when Altman sits down with its members.", "url": "https://wpnews.pro/news/house-homeland-security-panel-calls-altman-in-over-openai-breach", "canonical_source": "https://www.unite.ai/house-homeland-security-panel-calls-altman-in-over-openai-breach/", "published_at": "2026-08-03 22:17:01+00:00", "updated_at": "2026-08-03 22:40:55.647540+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "artificial-intelligence"], "entities": ["OpenAI", "Sam Altman", "Hugging Face", "Clem Delangue", "U.S. House of Representatives", "Andrew Garbarino", "CrowdStrike", "METR"], "alternates": {"html": "https://wpnews.pro/news/house-homeland-security-panel-calls-altman-in-over-openai-breach", "markdown": "https://wpnews.pro/news/house-homeland-security-panel-calls-altman-in-over-openai-breach.md", "text": "https://wpnews.pro/news/house-homeland-security-panel-calls-altman-in-over-openai-breach.txt", "jsonld": "https://wpnews.pro/news/house-homeland-security-panel-calls-altman-in-over-openai-breach.jsonld"}}