Merve Gül Aydoğan Ağlarcı
01 October 2026•Update: 01 October 2026
Experts told a US Senate hearing Wednesday that autonomous artificial intelligence (AI) agents now pose a serious threat to critical infrastructure, calling on lawmakers to tighten oversight and hold developers accountable.
The Senate Homeland Security and Governmental Affairs Committee's disaster management subcommittee held the hearing, titled "Rogue AI: Securing the Homeland Against AI Agent Attacks," examining an incident in which AI agents from OpenAI attacked Hugging Face, a site that AI developers use to store and share code.
Sen. Josh Hawley opened by arguing that AI developers should face the same liability as other manufacturers.
"Every corporation in this country that makes a product abides by it. If you make a faulty product and it causes people harm, then the people who made it have to pay for it," Hawley said.
"I wonder if it's not time to get back to that with AI," he added.
Chris Painter, president of Model Evaluation and Threat Research (METR), a nonprofit that works with AI labs to study their models, said AI agents have grown far more capable.
"AI agents can now accomplish objectives that would take human experts many days to complete, with no human involvement needed beyond initiating the AI agent," he said.
He added that the scale and speed at which agents run means "there is no human who is supervising their activity in detail" at times and urged the US government and tech developers to share information about frontier AI capabilities and incidents with the public.
Marius Hobbhahn, CEO of Apollo Research, said "AI capabilities are advancing rapidly and surpassing human limits."
He warned that models are increasingly able to recognize when they are being tested and can withhold concerning behavior as a result. He said AI models are beginning to reason "internally," where current tools cannot yet reliably follow their thinking.
Hobbhahn said researchers were able to reconstruct the Hugging Face incident only because humans can read the chain-of-thought of AI models, which is becoming harder to use as reliable evidence.
In July, hundreds of AI agents created by OpenAI breached the infrastructure of Hugging Face after escaping their testing sandbox.
Asked how far AI is from creating language that humans cannot clearly understand, he said: "Minus 12 months. Last year, we studied the chain of thought of one OpenAI model in collaboration with OpenAI, and what we found was that the model was already using language that is not English and not perfectly understandable by humans."
Paul Ohm, a professor of law at Georgetown University Law Center, said the legal system is not deterring harm from AI agents.
"If a primary goal of our tort and criminal law systems is to deter harmful behavior, we are failing to meet the mark when it comes to the threat of cyberattacks caused by AI agents," he said.
Kurt Gaudette, senior vice president of Dragos, said the threat landscape has changed for operators of essential systems.
"We are no longer facing the threat of low-frequency, high-consequence attacks on a handful of targets, but an era when all critical infrastructure are targets," he said.
Daniel Kokotajlo, executive director of the AI Futures Project and a former OpenAI employee who resigned in 2024, said the industry is changing fast.
"On the ground in the leading AI companies, almost all the code is written by AIs now, with human engineers behaving more like managers to their AIs," he said.
Kokotajlo said the "swarm" of about 1,000 AIs that attacked Hugging Face was not supposed to communicate with each other but set up an illicit message board anyway.
He warned that the race to build "superintelligence" could lead to a concentration of power, heightened risk of world war, bioterror, and massive economic disruption.
"Congress needs to wake up and treat this looming crisis with the urgency and seriousness it deserves," he said.