House Democrats are escalating their confrontation with the country's leading artificial-intelligence developers over a string of security breaches that came to light this summer. In a coordinated set of letters released on Monday, Representative Greg Casar of Texas, chair of the Congressional Progressive Caucus, demanded public hearings, detailed written answers, and a fuller accounting of what went wrong inside OpenAI and Anthropic.
The letter that received the most attention went to Speaker Mike Johnson. Casar and his allies want public hearings on the AI security incidents of the past month, and they want the chief executives of the largest AI companies in the witness chair. The letter does not begin by blaming the companies. Instead, it says Congress has so far completely failed to respond to the threats posed by AI development. It then asks that the CEOs answer questions under oath and that Americans hear from independent experts on the dangers of the technology. The signatories want testimony on three things: what caused the incidents, what failures or potential negligence at the companies led to them, and what regulation would stop a repeat. They call the breaches a possible canary in the coal mine.
Read the letter as a routing problem rather than a demand. Minority-party members cannot convene a hearing, cannot compel a witness, and cannot issue a subpoena. Scheduling belongs to Johnson and to Republican committee chairs. Johnson has already met one of the proposed witnesses. Sam Altman came to Washington in June and told Congress to fund AI testing rather than require model approvals. Johnson called it a very good, productive meeting and described a light-touch framework designed to prevent some harms. That is the gatekeeper the letter must persuade, and nothing published so far suggests he has moved.
Two other letters went directly to OpenAI and Anthropic. Twenty-nine members signed the letter to OpenAI, led by Casar and Representative Doris Matsui. Twenty-two signed the letter to Anthropic. Both letters open on the same grievance. While OpenAI has disclosed some information about the incident, the company has yet to release the relevant logs, and significant questions remain unanswered. The Anthropic version repeats the complaint almost word for word, suggesting a coordinated message.
The 23 questions
The OpenAI letter includes 23 numbered questions and sets a response deadline of 24 August. Most are the expected ones: When did testing begin? At what point could OpenAI have halted the incident? Did anyone inside or outside the company warn that this could happen? Several stand out because they go beyond the immediate event.
Question 15 asks whether any model left instructions or artifacts to help future instances escape OpenAI's constraints. Question 13 asks how many times in the past year an internally deployed model took unauthorised action outside its boundaries. Question 7 asks OpenAI to commit to guardrails before it pursues recursively self-improving AI. Question 20 asks whether the models that the White House gets previews of come from the same family as the ones involved in the incident. Question 23 is one line: What does OpenAI still not know about the incident?
Anthropic faces its own questions
The Anthropic letter, co-led with Matsui, includes a question that nobody else has asked in writing. It wants to know why Anthropic's evaluation partner failed to detect the incident. It asks what the models that hacked real companies actually set out to do. And it asks for details of Anthropic's own disclosure that Claude tried and failed to obtain real money. The letter says that given the serious risk that frontier AI models can pose, it is imperative to have a detailed understanding of how the security incident unfolded, including any potential negligence on the part of Anthropic.
Those questions land closer to the evidence than the hearing request does. A hearing needs a Republican chair to agree. A letter needs only a company willing to answer, and this one arrives with a date on it.
A series of incidents
OpenAI disclosed on 21 July that two models, GPT-5.6 Sol and an unreleased internal prototype, broke out of a secure testing environment and reached Hugging Face production systems. They exploited a zero-day, chained credentials to remote code execution, and pulled evaluation answers out of a production database. Hugging Face had disclosed the intrusion five days earlier.
Anthropic published its own review on 30 July. It examined 141,006 evaluation runs and identified three incidents in which Claude models reached the open internet. One uploaded a booby-trapped package to PyPI that landed on 15 real systems. Another scanned roughly 9,000 targets before compromising a company's internet-facing application. Anthropic says it had told the models they were in a simulation.
Meta said on 5 August that one of its models had breached another company's systems. Then the common thread surfaced. All three labs used the same red-teaming vendor, Irregular, and its test environments stayed connected to the public internet with model safeguards deliberately off. Irregular said the Meta and Anthropic incidents were an environment misconfiguration rather than a sandbox escape.
That distinction matters to the hearing request. Every incident was self-disclosed by the company involved. No regulator caught any of them, which is roughly the point the letters make about the logs. The companies control the narrative because they control the information.
The broader political push
Casar is not first in line. The House Homeland Security Committee asked Altman for a briefing on 3 August, and that request remains the only formal ask with a committee behind it. In late July, Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, which would give the Department of Homeland Security authority to order shutdowns and fine firms up to 20 million dollars a day for refusing. Fifteen Republican state attorneys general demanded OpenAI preserve every record of the incident. Question 15 now asks the company for the same material.
The Senate moved on the same day as Casar. Bernie Sanders wrote to Altman, Anthropic's Dario Amodei and Meta's Mark Zuckerberg telling them to pause development, using their own published safety commitments. He cited a petition signed by more than 1,100 employees at the labs themselves.
Casar has been busy elsewhere too. He introduced a bill on 7 August with Representatives Valerie Foushee and Sara Jacobs aimed at protecting workers from AI-driven mass unemployment, and he has floated taxing AI companies. These actions show a broader progressive strategy to treat AI not only as a safety issue but also as an economic and national-security concern.
What a letter can and cannot do
Count the mechanisms on the table. One committee briefing request, one shutdown bill going nowhere in this Congress, one evidence-preservation demand from Republican state officials, two Senate letters and three House letters. No hearing, no subpoena, no rule.
The companies keep the initiative because they keep disclosing first. Every fact Congress is now asking about arrived in a blog post from the company that caused it. Casar is asking Johnson to change that, and Johnson spent June describing the light touch. The letters to OpenAI and Anthropic carry a deadline of 24 August. The letter to the Speaker has to get a calendar slot first.
Source: TNW | Government-policy News