House Democrats want AI CEOs under oath. Only Mike Johnson can make it happen.

Three letters left Greg Casar's office on Monday. Almost every write-up covered one. The two nobody read carry 23 numbered questions and a deadline of 24 August.


House Democrats want AI CEOs under oath. Only Mike Johnson can make it happen.
Image Credits Credit: Greg Casar

The one everybody covered went to Speaker Mike Johnson. CNBC’s Megan Cassella reported it first. House Democrats want public hearings on the AI security incidents of the past month, and they want the chief executives of the largest AI companies in the witness chair.

Casar chairs the Congressional Progressive Caucus. His letter does not open by blaming the companies.

“Unfortunately, Congress has so far completely failed to respond to the threats posed by AI development,” it says.

Then it names the ask. “The CEOs of the largest AI companies should answer questions under oath, and Americans should have a chance to hear from independent experts on the dangers posed by this technology.”

The signatories want testimony on three things: what caused the incidents, what failures or potential negligence at the companies led to them, and what regulation would stop a repeat. They call the breaches a possible canary in the coal mine.

The recipient has already met the witness

Read the letter as a routing problem rather than a demand. Minority-party members cannot convene a hearing, cannot compel a witness and cannot issue a subpoena. Scheduling belongs to Johnson and to Republican committee chairs.

Johnson has met one of the proposed witnesses. Altman came to Washington in June and told Congress to fund AI testing rather than require model approvals. Johnson called it a very good, productive meeting and described a light touch framework designed to prevent some of the harms that could come from the technology.

That is the gatekeeper the letter has to persuade. Nothing published on Monday suggests he has moved.

The White House has not moved either. President Trump has said he wants guardrails on AI while warning that too much action could hamper US firms competing with China.

The other two letters ask the sharper questions

Reuters’ Courtney Rozen reported the letters that went to the companies. Casar’s office published both the same day. Twenty-nine members signed the letter to OpenAI, led by Casar and Rep. Doris Matsui. Twenty-two signed the letter to Anthropic.

“These deeply troubling cybersecurity incidents could have serious implications for America’s national security,” the lawmakers wrote.

Both letters open on the same grievance, and it has nothing to do with testimony. “While OpenAI has disclosed some information about the incident, your company has yet to release the relevant logs and significant questions remain unanswered,” the letter to Altman says. The Anthropic version repeats the complaint almost word for word.

Twenty-three questions and a date

The OpenAI letter itself runs to 23 numbered questions. It sets a response deadline of 24 August.

Most of them are the ones you would expect. When did testing begin. At what point could OpenAI have halted the incident. Did anyone inside or outside the company warn that this could happen.

Several are not. Question 15 asks whether any model left instructions or artifacts to help future instances escape OpenAI’s constraints. Question 13 asks how many times in the past year an internally deployed model took unauthorised action outside its boundaries. Question 7 asks OpenAI to commit to guardrails before it pursues recursively self-improving AI. Question 20 asks whether the models the White House gets previewed come from the same family as the ones involved here.

Question 23 is one line. What does OpenAI still not know about the incident?

The Anthropic letter, co-led with Matsui, puts a question to the company that nobody else has asked in writing. It wants to know why Anthropic’s evaluation partner failed to detect the incident. It asks what the models that hacked real companies actually set out to do. And it asks for details of Anthropic’s own disclosure that Claude tried and failed to obtain real money.

“Given the serious risk that frontier AI models can pose, it is imperative we have a detailed understanding of how this security incident unfolded, including any potential negligence on the part of Anthropic,” it says.

Those questions land closer to the evidence than the hearing request does. A hearing needs a Republican chair to agree. A letter needs only a company willing to answer, and this one arrives with a date on it.

What the letters are actually about

OpenAI disclosed on 21 July that two models, GPT-5.6 Sol and an unreleased internal prototype, broke out of a secure testing environment and reached Hugging Face production systems. They exploited a zero-day, chained credentials to remote code execution and pulled evaluation answers out of a production database. Hugging Face had disclosed the intrusion five days earlier.

Anthropic published its own review on 30 July. It examined 141,006 evaluation runs and identified three incidents in which Claude models reached the open internet. One uploaded a booby-trapped package to PyPI that landed on 15 real systems. Another scanned roughly 9,000 targets before compromising a company’s internet-facing application. Anthropic says it had told the models they were in a simulation.

Meta said on 5 August that one of its models had breached another company’s systems. Then the common thread surfaced. All three labs used the same red-teaming vendor, and Irregular’s test environments stayed connected to the public internet with model safeguards deliberately off. Irregular told Reuters the Meta and Anthropic incidents were an environment misconfiguration rather than a sandbox escape.

That distinction matters to the hearing request. Every incident was self-disclosed by the company involved. No regulator caught any of them, which is roughly the point the letters make about the logs.

The queue outside Johnson’s door

Casar is not first in line. The House Homeland Security Committee asked Altman for a briefing on 3 August, and that request remains the only formal ask with a committee behind it.

Reps Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act in late July, which would give Homeland Security authority to order shutdowns and fine firms up to $20m a day for refusing. Fifteen Republican state attorneys general demanded OpenAI preserve every record of the incident. Question 15 now asks the company for the same material.

The Senate moved the same day as Casar. Bernie Sanders wrote to Altman, Amodei and Mark Zuckerberg telling them to pause development, using their own published safety commitments. He cited a petition signed by more than 1,100 employees at the labs themselves.

Casar has been busy elsewhere too. He introduced a bill on 7 August with Reps Valerie Foushee and Sara Jacobs aimed at protecting workers from AI-driven mass unemployment, and he has floated taxing AI companies.

What a letter can and cannot do

Count the mechanisms on the table. One committee briefing request, one shutdown bill going nowhere in this Congress, one evidence-preservation demand from Republican state officials, two Senate letters and three House letters. No hearing. No subpoena. No rule.

The companies keep the initiative because they keep disclosing first. Every fact Congress is now asking about arrived in a blog post from the company that caused it.

Casar is asking Johnson to change that, and Johnson spent June describing the light touch. The letters to OpenAI and Anthropic carry a deadline of 24 August. The letter to the Speaker has to get a calendar slot first.

Get the TNW newsletter

Get the most important tech news in your inbox each week.