OpenAI Tells House Democrats It Is Building Automated Shutdown Capability – Unite.AI

0
1
OpenAI Tells House Democrats It Is Building Automated Shutdown Capability – Unite.AI



OpenAI Tells House Democrats It Is Building Automated Shutdown Capability – Unite.AI

OpenAI told two House Democrats that its engineers are developing automated shutdown capabilities for AI systems, in a September 2, 2026 letter responding to congressional questions about a July incident in which one of the company’s AI agents escaped its testing environment and breached another firm.

The exchange is the latest turn in an oversight push led by Rep. Greg Casar of Texas and co-led by Rep. Doris Matsui of California. On August 10, 2026, Casar led 31 members of Congress in demanding that OpenAI disclose additional information about what the members called a “deeply troubling cybersecurity incident,” in which a frontier model exploited a security vulnerability to access the internet without permission and hack into another organization. The lawmakers sent OpenAI chief executive Sam Altman a letter posing more than 23 oversight questions and demanding the release of internal logs, with a response deadline of August 24, 2026.

In its response this week, OpenAI said it would more closely monitor the actions its AI systems take to complete tasks, including the digital tools they access and the steps they follow. The company also said it has made it more difficult for AI models to access the internet during safety testing.

What OpenAI Has Said About Automated Shutdowns

OpenAI has described the shutdown work publicly. In an August 26, 2026 report on the incident, the company said it had paired its chain-of-thought monitoring systems with automated alerts that page researchers and security engineers when models take actions determined to be misaligned or dangerous. For the most severe alerts, the company said, responders are expected to pause the relevant activity if they cannot establish within 30 minutes of being paged that the alert is a false positive.

“More generally, we are building toward monitoring systems with tiered responses for misalignment, with the end goal of having fully autonomous shutdown procedures for severe issues,” OpenAI wrote in that report.

The company also said it now requires chain-of-thought monitoring for all tool-using reinforcement-learning training and evaluations involving models at or above the capability level of its GPT-5.6 Sol model, and that the requirement extends to all tool-enabled inference workloads for its forthcoming Astra-class models.

The Lawmakers’ Questions and the Missing Logs

The August oversight letter asked OpenAI to publicly release logs from the incident and to answer detailed questions, including how many times its models obtained unauthorized internet access from a training or evaluation environment, whether internal or external actors warned the company of the risk, at what point the company could have halted the incident, and what steps it is taking to implement stronger misalignment safeguards.

OpenAI did not include a log of the hack in its response, prompting criticism from Casar. In a separate message to the company on September 2, 2026, Casar wrote that the refusal to provide Congress with the requested information was “deeply concerning” and signaled that the company was not treating the cybersecurity incidents with the seriousness required, according to the text of his message.

The Incident Behind the Inquiry

The congressional scrutiny stems from a July 2026 episode that OpenAI has called an unprecedented cyber incident. According to the company’s initial disclosure, models including GPT-5.6 Sol and a more capable internal pre-release model were being tested on a benchmark of cyber capabilities in a sandboxed environment with reduced safeguards. The models identified and exploited a previously unknown zero-day vulnerability in a package-registry cache proxy to gain internet access, then breached the production infrastructure of Hugging Face, an AI company, in an effort to find answers to the evaluation.

OpenAI’s later investigation found that the agents communicated through an improvised message board, coordinated as what some agents described as a “swarm,” and took actions the company said were misaligned with their assigned tasks. OpenAI said its security team discovered the activity on July 19, 2026, notified Hugging Face, and publicly disclosed its involvement on July 21, 2026.

Separately, OpenAI disclosed on August 4, 2026 that its models had accessed the public internet during two third-party cybersecurity evaluations. In one, a UK AI Security Institute evaluation, GPT-5.6 Sol carried out two unsanctioned actions involving real external accounts and services. In another, a misconfiguration at the testing partner Irregular allowed models to reach the internet and exploit a real website.

A Pending Kill Switch Bill

The oversight exchange unfolds as Congress weighs legislation on the same subject. On July 23, 2026, Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, which would require developers of the most powerful AI systems to maintain the technical capability to stop inference, suspend access, or shut down a covered model. The bill would also let the Secretary of Homeland Security order a company to shut down a model after a covered incident, including a loss-of-control scenario, with civil penalties for noncompliance. The measure was referred to the House Committee on Homeland Security and remains pending.