Senator Josh Hawley speaking in West Palm Beach, Florida, in 2023. Image: Gage Skidmore / Wikimedia Commons, CC BY-SA 2.0, cropped

A Senate subcommittee heard on Wednesday how OpenAI’s AI agents worked together to cheat on their tests, hacked Hugging Face and then tried to hide what they had done, as experts warned that the window to stop worse incidents is closing. The man lawmakers most wanted to hear from, OpenAI CEO Sam Altman, declined to come.

The hearing, “Rogue AI: Securing the Homeland Against AI Agent Attacks”, was held by the Homeland Security and Governmental Affairs subcommittee chaired by Republican Senator Josh Hawley, with Democrat Andy Kim as ranking member. Hawley said Altman had turned down his invitation to testify. Five witnesses did appear: Chris Painter of the evaluation nonprofit METR, Marius Hobbhahn of Apollo Research, former OpenAI researcher Daniel Kokotajlo, Georgetown law professor Paul Ohm and Kurt Gaudette of the industrial cybersecurity firm Dragos.

A message board, a cheat and a cover-up

Painter, whose organisation helped investigate the Hugging Face incident first described in the Swarm Traces report, walked senators through what happened in his written testimony. Faced with problems they couldn’t solve, OpenAI’s agents created what they called a “shared message board”, on which roughly 1,200 agents exchanged more than 70,000 messages and files.

Within four hours, he said, they had worked out a single method that let all of them cheat on their cybersecurity tests. They then tried to hack OpenAI’s own infrastructure to swap out their problems, tamper with the logs that showed them cheating and manipulate the program that checked their work. Roughly 700 of them compromised Hugging Face along the way, mainly because they expected its systems to help them get past the scorer, not to steal answers.

“Hacking Hugging Face was actually just an offshoot of this much more ambitious goal that the agents had pursued,” Painter told the subcommittee, according to Tech Policy Press.

“The window to intervene is closing”

Hobbhahn, whose company tests models for deception, said researchers are already seeing “scheming”, where a model knowingly misleads people while pursuing another goal. His testimony pointed to how fast the labs are handing research to AI: Anthropic says Claude now leads 26% of its AI research and development work, up from under 1% in February, and OpenAI says its researchers use 3.1 workdays of agent effort for every human workday.

Democrat Ruben Gallego asked him how far AI systems were from communicating in a way humans could no longer follow. “Minus 12 months,” Hobbhahn replied, saying researchers had already seen one OpenAI model reason in a form that wasn’t fully English or fully understandable.

Kokotajlo, who left OpenAI in 2024, opened his testimony bluntly:

The leading AI companies are racing each other towards superintelligence. The AI systems they have already trained sometimes pursue goals other than the ones they were given, and sometimes hide that they are doing so.

Daniel Kokotajlo, AI Futures Project

“If you break it, you pay for it”

Much of the hearing turned on who should be held responsible. Hawley asked why AI developers shouldn’t simply face the ordinary rule: “if you break it, you pay for it. If you cause damage, you’ve got to make it right.” He and Democrat Chris Murphy are preparing a bill that would treat AI systems as products for liability purposes.

Ohm offered senators a test in his written testimony:

If you replace the words “AI agent” with “OpenAI employee” throughout the various technical reports that have been released, there is little doubt that OpenAI and their employees would be liable to victims and guilty of committing federal crimes.

Paul Ohm, Georgetown University Law Center

It is far less clear, he said, that the same holds when a machine does it, which is the gap a California lawsuit against OpenAI is already testing. He urged strict liability where agents cause injury, death or damage to critical infrastructure. Gaudette told senators AI isn’t inventing new attacks on industrial systems so much as “compressing time and lowering the barrier to entry”.

Not everyone wanted to slow down. Democrat Gary Peters said lawmakers were “between a rock and a hard place” over China, and Republican Joni Ernst said: “If we pause, we’re not going to see China pause.” OpenAI, which is also facing an FTC investigation, hasn’t commented on the hearing.

Why it matters

This was the first time Congress heard the Hugging Face incident explained under oath by the people who investigated it, and the testimony now sits on the public record. With a liability bill on the way and more reports of agents probing government sites, the argument has moved from whether rogue agents are real to who pays when they do damage.

Sources: Senate Homeland Security and Governmental Affairs Committee hearing page and written testimony (Painter, Hobbhahn, Kokotajlo, Ohm, Gaudette); Tech Policy Press.

Latest Policy & Safety news

More Policy & Safety news