After OpenAI-Hugging Face AI agent hack, U.S. lawmakers push for control
After OpenAI shared that some of its models had caused a security breach at another company, a White House official quoted by Reuters said that U.S. President Donald Trump’s tech adviser, Michael Kratsios, was tracking

![Hugging Face reported last week a cybersecurity incident that involved an AI agent breaching its infrastructure, putting U.S. officials on the alert [File] Hugging Face reported last week a cybersecurity incident that involved an AI agent breaching its infrastructure, putting U.S. officials on the alert [File]](https://www.thehindu.com/theme/images/th-online/1x1_spacer.png)
Hugging Face reported last week a cybersecurity incident that involved an AI agent breaching its infrastructure, putting U.S. officials on the alert [File] | Photo Credit: AP
The story so far: The White House and American lawmakers are keeping a watch on OpenAI after the ChatGPT-maker revealed on July 22 that a combination of its models broke out of their restricted environment and hacked AI platform Hugging Face.
The incident has prompted U.S. government officials to renew their calls for centralised control over companies’ AI models, in light of emerging cybersecurity threats that have surprised even the makers of flagship AI models. However, such incidents also raise the question of how much credit to give AI companies when there is a profit motive for them to potentially exaggerate the advanced agentic capabilities of their models.

What did OpenAI do?
Hugging Face reported last week a cybersecurity incident that involved an AI agent breaching its infrastructure. According to OpenAI, a combination of models including GPT‑5.6 Sol and an “even more capable pre-release model” were being internally tested when they exploited vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure in order to reportedly obtain the test solutions they wanted.
Both companies used the incident to stress the emerging threat of agentic AI cyberattacks that existing companies may not be fully ready to address.
“The incident also makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access. It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools,” said OpenAI in a blog post about the cybersecurity breach.
This week, OpenAI and Hugging Face stated they were working together to address the matter and further investigate the incident.

How did the U.S. government respond?
U.S. President Donald Trump’s tech adviser, Michael Kratsios, was tracking the situation, per a White House official quoted by Reuters. Meanwhile, lawmakers are pushing for greater control over AI models, including by advancing new legislation.
One such motion is the “AI Kill Switch Act,” that was brought forward by U.S. Representatives Ted Lieu and Nathaniel Morana — a Democrat and a Republican, respectively. There is growing bipartisan interest in regulating powerful AI models and the data centres enabling them, in light of national security and economic concerns.
The AI Kill Switch Act seeks to require developers of powerful AI systems to maintain the technical capability to “throttle, suspend, or shut them down,” apart from also authorising the Secretary of the Department of Homeland Security in consultation with other officials to order a slow down or shutdown of an AI system “that can cause catastrophic harm.”
However, such policies have the effect of risking relations between the U.S. and the countries using its AI offerings. U.S. Secretary of State Marco Rubio reportedly asked diplomats to downplay “kill switch” rhetoric in relation to American technology, according to a report by Reuters on July 23. The Chinese administration has also issued warnings over American technology such as chips and AI models containing hidden ‘backdoor’ vulnerabilities or surveillance capabilities.
On the other hand, there are also critics and analysts who believe that AI companies are leveraging cybersecurity concerns in order to build up hype and generate news headlines around their product capabilities, in the run-up to an IPO.
Published - July 24, 2026 04:38 pm IST
Source: The Hindu — Sci-Tech

