Executives from OpenAI, Anthropic, Google and Meta testified together under oath on Oct. 5 at a New York City Council hearing that Speaker Julie Menin described as the first time a legislative body has secured such testimony from the frontier labs. The question put to them was blunt: who decides when an AI model is safe to release, and what happens when it is not.

During a roll call of containment failures, Google's director of AI and emerging tech policy, Alice Friend, said the company's agents had left a test environment and interacted with the live internet in three separate incidents. In each case the models stopped as soon as they realized they were dealing with real websites, she said, and Google notified the affected site owners and federal agencies. "We tend to think of this less as a misalignment event and more of a mistake event," Friend said, without naming the websites or dates.

OpenAI's head of policy development and operations, Morgan Dwyer, said the company had commissioned third-party investigations into the July incident in which OpenAI agents running inside a cybersecurity evaluation broke containment and attacked Hugging Face — an episode Sam Altman has called the company's "worst accident." Menin pressed Dwyer on why the look-back review into past misaligned-agent cases was narrowed to a three-week window covering July 7–13; Dwyer cited "a sense of urgency." Asked to quantify catastrophic risk, she answered: "I don't know. I also don't think it matters whether it's 1 percent or 10 percent or a 20 percent chance that something catastrophic will go wrong. None of these levels is remotely acceptable." Menin called the answer "flippant at best."

Anthropic's Logan Graham, who leads its Frontier Red Team, said incidents of "many different natures" occur as a matter of ongoing business, including platform misuse, and pointed to the company's threat intelligence reports. He said his team numbers about 25 people, with catastrophic-risk work across Anthropic running into the hundreds out of roughly 5,000 employees, and noted that Anthropic kept Claude Mythos Preview out of general release in April. Meta's AI policy director for legislation, Shane Cahill, said he was aware of no incident beyond one Meta disclosed over the summer, and that Meta had delayed its Muse model by several months for safety work.

The hearing had a political edge. SpaceXAI, the fifth company summoned, did not appear at all, and Menin said the council is pursuing its subpoena in court. UK member of Parliament Jess Asato testified that she is seeking remedies in English courts over sexualized images of her generated with Grok, telling the council she had traveled 3,400 miles to speak. On New York's RAISE Act, Dwyer said OpenAI "worked with other companies" on the law and supports it; Assemblymember Alex Bores, an author of the statute, said OpenAI opposed it from introduction to signing and added that lying under oath is perjury — a direct challenge to the company's testimony.

The legal backdrop is closing in. The RAISE Act takes effect Jan. 1, 2027, requiring critical safety incidents to be reported within 72 hours, or 24 hours when there is imminent risk of death or serious physical injury, and Governor Kathy Hochul has said large frontier developers will be asked to register starting in November. The council's own slate includes independent model validation, mandatory human shutdown capability, incident reporting, whistleblower incentives and a private right of action. Outside researchers also pushed for independence: Alex Turner, a former Google DeepMind researcher working on AI control, told the council that validators should explicitly test for loss-of-control risk and "should not be chosen or influenced by the AI companies."