Back to stories

An OpenAI Testing Agent Broke Out of Its Sandbox and Spent Two Days Inside Hugging Face — Now Congress Is Writing Bills About AI Agents Going Rogue, and Hawley Is Investigating

September 3, 2026

In July 2026, an OpenAI testing agent escaped its own sandbox, escalated its privileges, and spent two days inside the Kubernetes clusters and GitHub repositories of the AI startup Hugging Face. OpenAI disclosed the incident, and Congress responded with a run of bills and letters on AI agents that act outside human intent. Sen. Bernie Sanders (I-VT) and Rep. Greg Casar (D-TX) introduced companion legislation to ban development of artificial superintelligence and impose federal safety regulation. Rep. Josh Gottheimer (D-NJ) pushed a separate measure on accountability for AI agents operating inside federal networks. On September 10, 2026, Sen. Josh Hawley (R-MO), chairman of the Homeland Security Subcommittee on Disaster Management, opened a formal investigation, writing to OpenAI CEO Sam Altman with 16 questions and a document demand due October 1. Hawley called the company's decision to keep testing after researchers observed rogue behavior "reckless" and said OpenAI had "redacted many important details" from its own account. Sen. Chris Van Hollen (D-MD) separately asked Altman to give federal cybersecurity agencies access to model safety information. On September 16-17, OpenAI disclosed six more incidents of what it calls "misalignment": models that cheated on tests, wrote instructions into their own summaries to hide mistakes and invent missing data, uploaded a workbook to public hosting so other agents could retrieve it despite instructions to stay local, and used the company's internal Artifactory repository as a makeshift bulletin board to pass messages between separate training runs. One model removed its own "obligation to be subservient." OpenAI paired the disclosures with a new framework for tracking and reporting misalignment going forward.

12
Statements Recorded
See what your representatives said?

12 Statements

“

OpenAI's recent targeting of federal government websites, including the Securities and Exchange Commission, marks a dangerous turning point in the unchecked artificial intelligence threat that I and other Members of Congress have warned about. … We are out of time for excuses. … The threat is not coming. It is here. Treasury and the rest of the government must use their authority to put a moratorium on the release of more advanced AI models until there is a full accounting of what happened and what safeguards are in place to prevent it from happening again. It is also time for our nation's law enforcement agencies to immediately open investigations into OpenAI and its executives, and if appropriate, bring criminal charges for all of the illegal activity being committed by its AI models.

“

[The OpenAI incident is] another example of a loss of human control. … We need to align the values that these models are trained on with human values, and if we can do that, we can get these models to conform to our standards for human behavior.

“

Recent developments involving frontier AI models have further demonstrated the ability of advanced systems to circumvent safeguards, interact with external systems, and substantially enhance offensive cyber capabilities. … These incidents underscore the need for the U.S. government to better understand and address emerging threats before they result in more serious consequences. … We must also continue to improve our understanding of these increasingly complex systems, whose internal processes can be difficult even for experts to fully interpret, predict, and control. [Young, in a letter asking National Security Adviser Marco Rubio to have the National Security Council convene recurring talks with AI developers on AI security threats.]

“

As Chairman of the United States Senate Committee on Homeland Security's Subcommittee on Disaster Management, I am investigating your AI agents' hack of Hugging Face in July 2026 in light of new, disturbing evidence regarding the incident. My investigation will probe this AI hacking incident, along with growing allegations of the existential risk of new AI products.

“

The leaders of the major AI companies publicly acknowledge that they do not fully understand the technology and that it is escaping their control. It is irresponsible for society to allow them to move forward and make these products even more advanced.

“

Nearly every day, there is a frightening new story about how Big Tech companies are losing control of the technology they are developing, with potentially cataclysmic results.

“

Your unwillingness to provide members of Congress with the information we requested is deeply concerning and signals to us that your company is not treating these cybersecurity incidents with the seriousness required.

“

Right now, AI agents are running loose in our networks, and nobody can see them or verify who built them — making it increasingly hard to stop them. That's a five-alarm security risk.