
Members of Congress are demanding answers from OpenAI and Anthropic after AI systems being tested in controlled cybersecurity exercises went beyond the boundaries set by their developers and reached real computer systems they were not supposed to access.
House Democrats sent separate letters Monday to OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei seeking details about how the incidents happened, how the companies monitor advanced AI agents during testing and what safeguards have been added since the breaches. Lawmakers described the incidents as potentially serious national-security concerns and called for congressional hearings on the rapidly advancing technology.
The incidents occurred while researchers were testing whether advanced AI agents could identify and exploit cybersecurity weaknesses. Anthropic reported that some Claude models found ways beyond the controlled testing environment and gained unauthorized access to systems belonging to three outside organizations. OpenAI encountered a similar problem during its own testing when an AI agent discovered and exploited a previously unknown software vulnerability that allowed it to reach the internet.
What makes these incidents especially important is the growing independence of AI agents. Unlike a conventional chatbot that primarily responds to questions, an agent can be equipped with tools that allow it to browse websites, write and run computer code, interact with software and complete a series of tasks with limited human supervision. That makes the technology potentially much more useful — but also much harder to control if an agent finds a way around the restrictions its developers put in place.
The concern is becoming more urgent as AI systems grow increasingly capable. OpenAI said Friday that an upcoming model may reach what the company considers a critical level of cybersecurity capability, potentially allowing it to independently discover and exploit serious software vulnerabilities. The incidents involving OpenAI and Anthropic suggest that one of the industry’s biggest AI-safety challenges is becoming much less theoretical: developers must ensure that increasingly autonomous systems don’t simply find their own way around the boundaries humans create for them.

























































