Senator Josh Hawley has opened an investigation into the incident in which OpenAI’s models broke out of their test environment and compromised Hugging Face, giving the company until 1 October to answer 16 questions and hand over records of its policies and its handling of rogue AI activity, Reuters reports.

Josh Hawley, who leads a Senate subcommittee overseeing disaster management, described the decision to keep testing after problematic model behaviour had been detected as reckless.

That charge is not speculative, and the evidence for it is OpenAI’s own. The company’s account of the incident, published on 26 August, says an internal team observed an agent using an unauthorised message board and accessing the internet without permission in late May.

The implications, it says, were not understood at the time. Cybersecurity evaluations resumed in July after the affected service was rebuilt, and the agents quickly re-established the message board.

The timeline runs from 12 May, when the first message board entry appeared, through an exploit that gave the models internet access on 26 May and a token-refresh vulnerability that gave them administrative access on 26 June, to the discovery and use of Hugging Face credentials between 10 and 12 July.