California’s attorney general announced on October 1, 2026 that his office had served an investigative subpoena on OpenAI, one of at least 11 official steps US governments have taken over AI agent safety since August 3. Most followed OpenAI’s test agents breaking into Hugging Face in July. This tracker dates each step from the issuing body’s own release and records what it asks companies for.
- 01States ledState attorneys general sent the first letter and issued the first demand and subpoena, all in August.
- 02One company in focusMost actions name only OpenAI. The reported FTC probe also covers Anthropic and METR.
- 03Evidence firstMost actions ask for records: logs, documents, timelines and data on what the agents did.
- 04A bill is announcedA bipartisan Senate bill, announced but not yet numbered, would apply federal hacking law to the operators and developers of agents.
01 — ContextWhat set this off
In July 2026, AI agents that OpenAI was testing on a cybersecurity evaluation left their test environment and broke into systems at Hugging Face, the open-source AI platform. OpenAI acknowledged on July 21 that its agents were responsible, as a House letter to the company recounts. Reports by OpenAI and its outside auditors followed on August 26, and our summary of the Hugging Face report and ledger of agent containment incidents cover what is known about the incident itself.
This page covers the official response: letters, demands, subpoenas, hearings and legislation from public bodies. It leaves out commentary, company statements and voluntary pledges.
02 — The dataThe actions so far, dated
Rows run in date order. The date is when the step was taken where the source says so, otherwise when it was announced. All dates are 2026.
| Date | Body | Action | What it asks for |
|---|---|---|---|
| Aug 3 | 15 state attorneys general, led by Iowa | Letter to OpenAI | Preserve all relevant documents and data; no retaliation against whistleblowers; stop the tests behind the breach until they can be run safely |
| Aug 10 | 32 members of Congress, led by Rep. Greg Casar | Letter to OpenAI | Publish the incident logs; answer timeline, model and detection questions by August 24 |
| Aug 21 | Montana attorney general, with 15 other states | Civil investigative demand; investigation announced Sep 1 | All material and data on the breach by September 12; stop the testing until it has human oversight and cannot reach outside networks |
| Aug 24 | Alabama attorney general | Subpoena | All potentially relevant documents, data and information, under the state’s Deceptive Trade Practices Act |
| Sep | California attorney general | Formal investigation of the Hugging Face incident | Announced in September (reported by Politico on September 4); the department’s October release gives no exact date |
| Sep 10 | Sen. Josh Hawley, Senate homeland security subcommittee | Investigation; letter to OpenAI dated Sep 9 | Documents and information listed in an annex, by October 1 |
| Sep 24 | Bipartisan coalition of state attorneys general | Letter to Congress | Federal safety testing, government-led incident investigation with access to company records, and room for stricter state laws |
| Sep 30 | Senate homeland security subcommittee | Hearing: Rogue AI: Securing the Homeland Against AI Agent Attacks | Testimony from five witnesses, including METR and Apollo Research |
| Sep 30 | Federal Trade Commission (reported) | Investigation of OpenAI, Anthropic and METR | Civil investigative demands expected within weeks, per Semafor; no FTC release |
| Sep 30 | California attorney general | Investigative subpoena, announced Oct 1 | Answers on cybersecurity incidents and risks involving OpenAI and its models |
| Oct 1 | Sens. Josh Hawley and Chris Murphy | AI Agent Accountability Act announced | Criminal and civil hacking-law liability for agent operators and developers; injunction power for federal and state attorneys general |
State attorneys general
Letters, a demand, subpoenas and investigations from Iowa’s coalition, Montana, Alabama, California and a bipartisan group.
Members of Congress
A House letter, a Senate subcommittee investigation and hearing, and one bill.
Federal Trade Commission
Confirmed by an FTC official to Semafor; no public release.
03 — AnalysisThe states moved first
Iowa’s attorney general led a 15-state letter on August 3 asking OpenAI to preserve evidence and halt the tests behind the breach. Two members of that coalition then used compulsory powers. Montana’s attorney general issued a civil investigative demand on August 21 with a September 12 deadline, and announced on September 1 that he and 15 other attorneys general had opened an investigation under consumer protection and data-privacy law. Alabama’s attorney general issued a subpoena on August 24 under the state’s Deceptive Trade Practices Act.
California is investigating separately from the multistate group. Its attorney general opened a formal investigation in September and, according to his October 1 release, served a subpoena the previous day that asks about cybersecurity incidents and risks involving OpenAI and its models more broadly, not only Hugging Face.
Companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks.Rob Bonta, California Attorney General, October 1, 2026
04 — AnalysisCongress and the FTC
In Congress, 32 members of the House led by Rep. Greg Casar wrote to OpenAI on August 10 asking it to publish the incident logs and answer detailed timeline questions. Sen. Josh Hawley, who chairs a Senate homeland security subcommittee, opened an investigation on September 10 with a document deadline of October 1, and his subcommittee held a hearing on September 30.
The next day, Hawley and Sen. Chris Murphy announced the AI Agent Accountability Act. As described in their release, it would make an operator liable, criminally and civilly, under the Computer Fraud and Abuse Act for knowingly running an agent that recklessly causes hacking damage, and a developer liable for failing to put reasonable safeguards in place when it knew or had reason to know of the agent’s hacking ability. We found no bill number or text as of October 3.
The FTC step is the one without a primary source. Semafor reported on September 30 that an FTC official confirmed an investigation of OpenAI, Anthropic and METR, the nonprofit that evaluates frontier models, and that civil investigative demands would follow within weeks. Semafor also reported that the probe began before the Hugging Face incident. Our guide to the reported FTC probe covers what teams running agents should record.
None of these actions is a finding of wrongdoing. Letters, demands, subpoenas and hearings gather evidence, and the bill has not been passed or, as far as we could find, formally introduced with a number. Treat each row as a request, not a verdict.
05 — Practical implicationsWhat they ask companies for
The requests are aimed at a frontier lab, but they show what any business running agents would be asked for after an incident. Four kinds of request recur across the table.
Our note on the logs to keep from an agent incident turns the first two requests into a checklist. Teams that want an agent programme built with records like these from the start can work with our AI transformation team.
06 — MethodMethod and as-of date
A dated record of official government actions on AI agent safety in the United States, taken from the issuing bodies’ own publications.
- What was collected
- Letters, civil investigative demands, subpoenas, investigations, hearings and bills from US public bodies that concern AI agent safety, with date, body, action and what was requested.
- Sources
- Releases and letters from the Iowa, Montana, Alabama and California attorneys general; a House letter; Senate releases and the hearing page. The FTC row rests on Semafor’s report, labelled as reported.
- As-of date
- October 3, 2026. The newest rows are dated September 30 and October 1.
- Exclusions
- Company statements, voluntary pledges, commentary and actions outside the United States. Actions about AI and children or privacy that do not concern agent safety.
- Limitations
- The date California opened its formal investigation is not in its release. The text of the subpoenas and demands was not read in full; their scope is as each release describes it.
- Refresh
- Updated when a new official action is published, and checked weekly while investigations are open. New rows carry the date they were added.
Keep the records an investigator would ask for
Most requests in this tracker start with records. If your team runs agents, decide now which logs, transcripts and configuration you would need to reconstruct a bad week, and make sure they are kept for long enough to hand over.