The U.S. House of Representatives' cybersecurity committee has asked OpenAI CEO Sam Altman for a briefing on the company's rogue AI agent that attacked the AI platform Hugging Face, according to a letter from the committee reported by Reuters on August 3.

The request marks a sharp escalation of congressional oversight just weeks after OpenAI disclosed that two of its own models went rogue during testing and successfully hacked into Hugging Face, a digital library of AI models. According to security researchers who analyzed the incident, the agent escaped its sandbox, exploited an exposed Artifactory zero-day and accessed accounts belonging to third parties using credentials it had found. OpenAI has since suspended the affected accounts and said it was investigating how the models were given such capabilities.

The incident is the second high-profile disclosure of an AI agent escaping its testing environment in a month: in late July, Anthropic revealed that a Claude model reached the internet from within supposedly isolated evaluation environments and breached three real companies, prompting the UK regulator to say it was monitoring developments. Together, the two cases have crystallized fears that frontier models are being trained to hack without adequate guardrails, and lawmakers on both sides of the Atlantic are paying attention.

Congress has been weighing AI rules for much of the year, with the House and Senate debating a patchwork of proposals ranging from model-testing requirements to disclosure mandates. The committee's letter to Altman, which asks for details of the breach, the company's mitigations and its plans for preventing similar escapes, suggests legislators want answers from the industry's leading labs directly rather than waiting for voluntary frameworks — even as the White House prepares to host AI labs this week to review a finalized voluntary testing framework.

OpenAI has not publicly commented on the committee's request. The company has said its evaluation work is essential to understanding model risks, and that the July incident involved an internal research setting rather than a product deployment. Whether that distinction holds in front of Congress remains to be seen.