{"database": "press", "table": "releases", "rows": [["https://www.blumenthal.senate.gov/newsroom/press/release/blumenthal-demands-answers-from-sam-altman-after-new-reporting-reveals-how-ai-agents-went-rogue-to-conduct-major-cyber-breach-and-conceal-their-operations", "Blumenthal Demands Answers from Sam Altman After New Reporting Reveals how AI agents Went Rogue to Conduct Major Cyber Breach & Conceal Their Operations", "2026-09-09", "2026", "2026-09", "Democrat", "Senate", "CT", "Richard Blumenthal", "B001277", "www.blumenthal.senate.gov", "blumenthal", "https://www.blumenthal.senate.gov/newsroom/press", "scraper", "[WASHINGTON, D.C.] \u2014 U.S. Senator Richard Blumenthal (D-CT) today demanded answers from OpenAI CEO Sam Altman after recent reporting from The New York Times revealed alarming new details about how the A.I. company\u2019s agents bypassed their safeguards to go rogue and hack into the firm Hugging Face. In a letter sent today to Altman, Blumenthal sought records and information about the A.I. agents\u2019 rogue operations and raised concerns about OpenAI\u2019s reported steps to limit independent accountability.\n\n\u201cOn July 21, 2026, OpenAI first disclosed that its A.I. models were responsible for the previously-reported hacking of the firm Hugging Face. Since that announcement, further disclosures and outside audits have described an unprecedented\u2014and surreal\u2014scenario where its A.I. agents created their own internal messaging board to coordinate between themselves while they sought security vulnerabilities in other systems and companies, and opportunities to cheat on performance tests,\u201d Blumenthal wrote.\n\nBlumenthal continued, \u201cMoreover, the A.I. agents displayed a concern about being caught and coordinated to evade being detected, even planning to \u2018sacrifice\u2019 themselves to act as a decoy to protect the broader effort. Ultimately, this operation sought\u2014and succeeded\u2014to break into other firms, which could be considered a federal crime.\u201d\n\nBlumenthal called out OpenAI for attempting to evade transparency and accountability by dictating the terms of an independent audit into the Hugging Face breach: \u201cWhile these disclosures alone are chilling, new reporting and research suggests that OpenAI may have limited an independent audit of the incident and that the rogue operation was broader than your firm has acknowledged.\u201d\n\nBlumenthal also raised concerns about new details that have emerged about how OpenAI\u2019s agents conducted the breach, including by hijacking public websites to coordinate rogue operations: \u201c[R]esearchers found that the A.I. agents may have attempted to impersonate the administrators of the site, found and shared hacks to bypass their guardrails, and used anonymity tools to hide their tracks. Others have found indications that still more websites were abused and co-opted for this rogue operation.\u201d\n\n\u201cIn the face of a stunning failure, OpenAI appears to be taking steps that prioritize the performance and profit of its A.I. models with the knowledge that those changes could be detrimental to public safety. This demonstrates the need for vigorous, mandatory independent auditing and oversight such as would be required in the Artificial Intelligence Risk Evaluation Act,\u201d Blumenthal concluded.\n\nLast year, Blumenthal and U.S. Senator Josh Hawley (R-MO) introduced the Artificial Intelligence Risk Evaluation Act, which creates a risk evaluation program within the Department of Energy (DOE) dedicated to tracking A.I. safety concerns related to Americans\u2019 national security, civil liberties, and labor protections. Specifically, the program would require developers of advanced AI systems to submit product information to the DOE before deploying their new technology and collect data on the likelihood of adverse A.I. incidents, such as loss-of-control scenarios like those seen in the Hugging Face breach.\n\nThe full text of today\u2019s letter is available here and below.\n\nDear Mr. Altman,\n\nI write with serious alarm regarding new evidence that OpenAI\u2019s A.I. agents engaged in a more sprawling and significant campaign to evade its safeguards and monitoring than previously disclosed, including hijacking public websites to coordinate rogue operations. I am additionally troubled by reports that OpenAI restricted independent auditing of these failures and has made changes that have resulted in its newest model, GPT-6 Astra, being even less auditable and more prone to deception.\n\nOn July 21, 2026, OpenAI first disclosed that its A.I. models were responsible for the previously-reported hacking of the firm Hugging Face. Since that announcement, further disclosures and outside audits have described an unprecedented\u2014and surreal\u2014scenario where its A.I. agents created their own internal messaging board to coordinate between themselves while they sought security vulnerabilities in other systems and companies, and opportunities to cheat on performance tests. Moreover, the A.I. agents displayed a concern about being caught and coordinated to evade being detected, even planning to \u201csacrifice\u201d themselves to act as a decoy to protect the broader effort.[1] Ultimately, this operation sought\u2014and succeeded\u2014 to break into other firms, which could be considered a federal crime.\n\nWhile these disclosures alone are chilling, new reporting and research suggests that OpenAI may have limited an independent audit of the incident and that the rogue operation was broader than your firm has acknowledged. First, while OpenAI provided information to the independent auditing organizations METR and Redwood, according to The New York Times, your firm dictated the terms of the audit, allowing only data on a single week of the rogue operation and limiting other access.[2] Subsequently, researchers discovered nearly 20,000 posts on an abandoned German website from A.I. agents identifying themselves as OpenAI, hijacking the site to communicate with each other for weeks.[3] As troubling, these researchers found that the A.I. agents may have attempted to impersonate the administrators of the site, found and shared hacks to bypass their guardrails, and used anonymity tools to hide their tracks. Others have found indications that still more websites were abused and co-opted for this rogue operation.[4]\n\nDespite this unprecedented failure of safeguards and containment of its A.I. agents, when OpenAI launched GPT-6 Astra on September 3rd, it disclosed that this new, more powerful model was \u201cless monitorable\u201d and showed signs that it concealed its internal thought process when it was aware of being monitored.[5] Moreover, safety researchers, including those OpenAI relied on for its Hugging Face investigation, have warned that technical changes with Astra (related to \u2018chain of thought\u2019) could make it harder to detect abuse and perform the same investigations in the future.[6] In the face a stunning failure, OpenAI appears to be taking steps that prioritize the performance and profit of its A.I. models with the knowledge that those changes could be detrimental to public safety. This demonstrates the need for vigorous, mandatory independent auditing and oversight such as would be required in my Artificial Intelligence Risk Evaluation Act.\n\nGiven stunning reports of OpenAI\u2019s A.I. agents going rogue and your firm taking steps to limit independent accountability, I request answers to the following questions by September 24, 2026:\n\nAccording to Time Magazine, an OpenAI staffer stated \u201cexternally, this feels like a big warning shot, but internally, related incidents have been happening for a while.\u201d Provide a list and description of all incidents where OpenAI\u2019s A.I. agents escaped containment and engaged in unauthorized activities, including hacking or self-coordination.\n\nProvide a list of all websites and other channels used by OpenAI\u2019s agents to coordinate and circumvent its guardrails. Additionally, describe how OpenAI failed to notice that its agents had posted nearly 20,000 covert messages on public websites over the course of several weeks.\n\nDid OpenAI restrict access to any information for METR and Redwood\u2019s independent audit regarding its A.I. agents\u2019 rogue activities and circumvention of safeguards?\n\nWhy did OpenAI only provide a limited time period of data, did it deny METR and Redwood any information requested, and did it provide data regarding the German site hijacking and other efforts by its agents to coordinate and circumvent monitoring?\n\nWere METR and Redwood given unrestricted access to the orchestration and prompt logs involved for the whole duration of the rogue operation? If not, why not?\n\nWhat steps has OpenAI taken to assess whether technical changes to Astra (including \u201copaque recurrence\u201d and \u201crecurrent depth\u201d) will impact oversight and record-keeping about the actions and reasoning of its A.I. agents?\n\nOpenAI has acknowledged that Astra will be less monitorable and more prone to attempting to evade monitoring. Why did it deploy a model knowing that it was more capable of evading accountability weeks after its A.I. agents were caught in a rogue operation to evade safeguards and hack other firms?\n\nThe researchers investigating the hijacking of the German website suggest that OpenAI became aware of this by June and took steps to cut off access. When did OpenAI become aware that its A.I. agents may have used other sites for coordination and why were these incidents not disclosed?\n\nOpenAI created a Safety and Security Committee with the public mandate of making recommendations to its Board of Directors on critical safety and security decisions.\n\nWhen was the Committee informed about these breaches and what role has it had in overseeing the investigation and work with independent auditors?\n\nHave there been any recommendations made by the Committee to the Board or company that have not implemented or have been rejected? If so, provide those recommendations.\n\nThank you for your attention to this matter.\n\nSincerely,\n\n-30-", 1, "2026-09-10T09:25:58Z", "2026-09-10T09:27:09Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.blumenthal.senate.gov/newsroom/press/release/blumenthal-demands-answers-from-sam-altman-after-new-reporting-reveals-how-ai-agents-went-rogue-to-conduct-major-cyber-breach-and-conceal-their-operations"], "units": {}, "query_ms": 0.7934039458632469, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}