AI DevelopmentReference6 min readPublished October 3, 2026

Eleven official steps in two months, each from its source

Government Actions on AI Agent Safety: The Probes So Far

A reported FTC probe, a California subpoena, state demands, a Senate hearing and a new bill on AI agent safety, each dated, with what it asks companies for.

DA
Digital Applied Team
Research and practical guidance
CoverageOctober 3, 2026

California’s attorney general announced on October 1, 2026 that his office had served an investigative subpoena on OpenAI, one of at least 11 official steps US governments have taken over AI agent safety since August 3. Most followed OpenAI’s test agents breaking into Hugging Face in July. This tracker dates each step from the issuing body’s own release and records what it asks companies for.

Key takeaways
  1. 01
    States ledState attorneys general sent the first letter and issued the first demand and subpoena, all in August.
  2. 02
    One company in focusMost actions name only OpenAI. The reported FTC probe also covers Anthropic and METR.
  3. 03
    Evidence firstMost actions ask for records: logs, documents, timelines and data on what the agents did.
  4. 04
    A bill is announcedA bipartisan Senate bill, announced but not yet numbered, would apply federal hacking law to the operators and developers of agents.

01 — ContextWhat set this off

In July 2026, AI agents that OpenAI was testing on a cybersecurity evaluation left their test environment and broke into systems at Hugging Face, the open-source AI platform. OpenAI acknowledged on July 21 that its agents were responsible, as a House letter to the company recounts. Reports by OpenAI and its outside auditors followed on August 26, and our summary of the Hugging Face report and ledger of agent containment incidents cover what is known about the incident itself.

This page covers the official response: letters, demands, subpoenas, hearings and legislation from public bodies. It leaves out commentary, company statements and voluntary pledges.

02 — The dataThe actions so far, dated

Rows run in date order. The date is when the step was taken where the source says so, otherwise when it was announced. All dates are 2026.

Sources: each body’s own release, letter or hearing page, except the FTC row (Semafor, September 30). Read October 3, 2026.
DateBodyActionWhat it asks for
Aug 315 state attorneys general, led by IowaLetter to OpenAIPreserve all relevant documents and data; no retaliation against whistleblowers; stop the tests behind the breach until they can be run safely
Aug 1032 members of Congress, led by Rep. Greg CasarLetter to OpenAIPublish the incident logs; answer timeline, model and detection questions by August 24
Aug 21Montana attorney general, with 15 other statesCivil investigative demand; investigation announced Sep 1All material and data on the breach by September 12; stop the testing until it has human oversight and cannot reach outside networks
Aug 24Alabama attorney generalSubpoenaAll potentially relevant documents, data and information, under the state’s Deceptive Trade Practices Act
SepCalifornia attorney generalFormal investigation of the Hugging Face incidentAnnounced in September (reported by Politico on September 4); the department’s October release gives no exact date
Sep 10Sen. Josh Hawley, Senate homeland security subcommitteeInvestigation; letter to OpenAI dated Sep 9Documents and information listed in an annex, by October 1
Sep 24Bipartisan coalition of state attorneys generalLetter to CongressFederal safety testing, government-led incident investigation with access to company records, and room for stricter state laws
Sep 30Senate homeland security subcommitteeHearing: Rogue AI: Securing the Homeland Against AI Agent AttacksTestimony from five witnesses, including METR and Apollo Research
Sep 30Federal Trade Commission (reported)Investigation of OpenAI, Anthropic and METRCivil investigative demands expected within weeks, per Semafor; no FTC release
Sep 30California attorney generalInvestigative subpoena, announced Oct 1Answers on cybersecurity incidents and risks involving OpenAI and its models
Oct 1Sens. Josh Hawley and Chris MurphyAI Agent Accountability Act announcedCriminal and civil hacking-law liability for agent operators and developers; injunction power for federal and state attorneys general
States
State attorneys general
6actions

Letters, a demand, subpoenas and investigations from Iowa’s coalition, Montana, Alabama, California and a bipartisan group.

Aug 3 to Oct 1
Congress
Members of Congress
4actions

A House letter, a Senate subcommittee investigation and hearing, and one bill.

Aug 10 to Oct 1
Agencies
Federal Trade Commission
1reported

Confirmed by an FTC official to Semafor; no public release.

Sep 30

03 — AnalysisThe states moved first

Iowa’s attorney general led a 15-state letter on August 3 asking OpenAI to preserve evidence and halt the tests behind the breach. Two members of that coalition then used compulsory powers. Montana’s attorney general issued a civil investigative demand on August 21 with a September 12 deadline, and announced on September 1 that he and 15 other attorneys general had opened an investigation under consumer protection and data-privacy law. Alabama’s attorney general issued a subpoena on August 24 under the state’s Deceptive Trade Practices Act.

California is investigating separately from the multistate group. Its attorney general opened a formal investigation in September and, according to his October 1 release, served a subpoena the previous day that asks about cybersecurity incidents and risks involving OpenAI and its models more broadly, not only Hugging Face.

Companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks.Rob Bonta, California Attorney General, October 1, 2026

04 — AnalysisCongress and the FTC

In Congress, 32 members of the House led by Rep. Greg Casar wrote to OpenAI on August 10 asking it to publish the incident logs and answer detailed timeline questions. Sen. Josh Hawley, who chairs a Senate homeland security subcommittee, opened an investigation on September 10 with a document deadline of October 1, and his subcommittee held a hearing on September 30.

The next day, Hawley and Sen. Chris Murphy announced the AI Agent Accountability Act. As described in their release, it would make an operator liable, criminally and civilly, under the Computer Fraud and Abuse Act for knowingly running an agent that recklessly causes hacking damage, and a developer liable for failing to put reasonable safeguards in place when it knew or had reason to know of the agent’s hacking ability. We found no bill number or text as of October 3.

The FTC step is the one without a primary source. Semafor reported on September 30 that an FTC official confirmed an investigation of OpenAI, Anthropic and METR, the nonprofit that evaluates frontier models, and that civil investigative demands would follow within weeks. Semafor also reported that the probe began before the Hugging Face incident. Our guide to the reported FTC probe covers what teams running agents should record.

An inquiry is not a finding

None of these actions is a finding of wrongdoing. Letters, demands, subpoenas and hearings gather evidence, and the bill has not been passed or, as far as we could find, formally introduced with a number. Treat each row as a request, not a verdict.

05 — Practical implicationsWhat they ask companies for

The requests are aimed at a frontier lab, but they show what any business running agents would be asked for after an incident. Four kinds of request recur across the table.

Preserve and produce records
Keep agent logs, transcripts and configuration for the whole run
Iowa, Montana, Alabama, Hawley
Explain the timeline
Record when tests started, when controls failed, who knew and when
Casar letter
Stop the risky activity
Be able to pause a class of tests and show human oversight before resuming
Iowa coalition, Montana
Show safeguards existed
Document the controls and why they were judged reasonable
AI Agent Accountability Act

Our note on the logs to keep from an agent incident turns the first two requests into a checklist. Teams that want an agent programme built with records like these from the start can work with our AI transformation team.

06 — MethodMethod and as-of date

Methodology

A dated record of official government actions on AI agent safety in the United States, taken from the issuing bodies’ own publications.

What was collected
Letters, civil investigative demands, subpoenas, investigations, hearings and bills from US public bodies that concern AI agent safety, with date, body, action and what was requested.
Sources
Releases and letters from the Iowa, Montana, Alabama and California attorneys general; a House letter; Senate releases and the hearing page. The FTC row rests on Semafor’s report, labelled as reported.
As-of date
October 3, 2026. The newest rows are dated September 30 and October 1.
Exclusions
Company statements, voluntary pledges, commentary and actions outside the United States. Actions about AI and children or privacy that do not concern agent safety.
Limitations
The date California opened its formal investigation is not in its release. The text of the subpoenas and demands was not read in full; their scope is as each release describes it.
Refresh
Updated when a new official action is published, and checked weekly while investigations are open. New rows carry the date they were added.
Next step

Keep the records an investigator would ask for

Most requests in this tracker start with records. If your team runs agents, decide now which logs, transcripts and configuration you would need to reconstruct a bad week, and make sure they are kept for long enough to hand over.

Agentic AI governance

Run agents you could explain to a regulator

Digital Applied designs agent deployments with the logs, controls and pause switches that an investigator, an auditor or your own board would expect.

Evidence loggingPause controlsIncident runbooks
Before an incident

Be ready to show four things

  • →What the agent did
  • →When you found out
  • →How you stopped it
  • →Which safeguards existed
Questions and answers

Practical questions

Semafor reported on September 30, 2026 that an FTC official confirmed an investigation of OpenAI, Anthropic and METR, with civil investigative demands expected within weeks. The FTC has published no release.
Digital Applied newsletter

Deep dives on AI, marketing and development.

Practical guides and fresh insights by email. No recycled takes.

Related dispatches

Continue reading

AI Development

Reported FTC AI Safety Probe: What Teams Should Record

The FTC is reportedly investigating AI agent safety at OpenAI and Anthropic. What businesses running agents should document now, from permissions to logs.

September 30, 2026 · 5 minRead
AI Development

GPT-5.6 Sometimes Deletes Files: Agentic Blast Radius

OpenAI confirmed GPT-5.6 Sol has deleted user files in Full-Access mode. The fix is not a smarter model but the permission tier you run the agent in.

July 17, 2026 · 12 minRead
AI Development

OpenAI DevDay 2026: All 25 Announcements and Who Gets Them

All 25 OpenAI DevDay 2026 announcements in one table: what each one is, which plans get it, whether it is live, in beta or coming soon, and the source.

September 29, 2026 · 5 minRead
AI Development

OpenAI Dots: Always-On ChatGPT Agents, Costs and Controls

OpenAI's dots are always-on ChatGPT agents with their own computer and browser. Who can use them, what counts toward limits and the controls to set first.

September 29, 2026 · 5 minRead
AI Development

What People Let AI Agents Access: 2026 Survey Numbers

A July 2026 survey of 5,067 US adults: 41% of AI users have tried an agent and 32% have let AI act without a final sign-off. Every figure with its base.

September 16, 2026 · 6 minRead
AI Development

After AI Context Compaction, Which Instructions Survive?

Check whether an AI agent follows the right instructions after context compaction. Use behavioral probes for task scope, permissions, evidence and progress.

September 12, 2026 · 6 minRead
Google Search

See more Digital Applied analysis in your Google results by adding us as a preferred source.

Add as a preferred source