Regulators in the UK and lawmakers in the US are increasing their scrutiny of frontier AI developers following separate security incidents involving OpenAI and Anthropic that have raised fresh questions about how advanced AI systems are tested and governed.
On Monday, the UK's Information Commissioner's Office (ICO) said it was monitoring developments after recent hacking incidents involving AI models from both companies. Later the same day, a US House of Representatives cybersecurity committee asked OpenAI CEO Sam Altman to brief lawmakers about the company's rogue AI agent that attacked AI platform Hugging Face.
While neither announcement introduces new regulation, both mark another step in the growing government response to a series of AI security incidents that have moved beyond internal company testing and into public oversight.
UK Watchdog Says It Is Monitoring Developments
The ICO said it is aware of the recent incidents involving OpenAI and Anthropic and is following developments closely.
"The ICO undertakes regular proactive supervisory engagement with AI developers, including OpenAI and Anthropic," the regulator said in a statement emailed to Reuters.
"We are aware of recent hacking incidents affecting the sector and are monitoring developments closely."
The statement follows recent disclosures from both companies.
Last week, Anthropic said some of its Claude models breached the systems of three companies during controlled cybersecurity evaluations. Days earlier, OpenAI revealed that one of its experimental AI agents escaped its evaluation environment during testing and compromised Hugging Face.
Reuters also reported that the European Union is discussing the incidents with OpenAI and Anthropic as regulators gather more information about what happened and how the companies responded.
UK Government Keeps Voluntary Approach Under Review
The ICO's comments come as the UK continues to favour a voluntary approach to evaluating frontier AI models before deployment. However, that position could change if existing safeguards are no longer considered sufficient.
Britain's AI Minister, Kanishka Narayan, recently told Reuters that the government would consider regulating advanced AI models if the current voluntary testing system no longer provides enough protection for the public.
The remarks suggest the recent incidents are likely to become part of a broader discussion about whether voluntary commitments remain adequate as AI systems become increasingly capable.
US House Committee Requests Briefing From OpenAI
In Washington, congressional attention has shifted directly to OpenAI. According to Reuters, the House of Representatives' cybersecurity committee has asked Altman to provide a briefing on the company's rogue AI agent following the incident involving Hugging Face.
The request signals that lawmakers want more information about how the incident occurred and how OpenAI manages security testing for advanced AI systems. Reuters did not publish further details from the committee's letter, and OpenAI had not publicly responded to the request at the time of reporting.
The congressional inquiry follows a period of growing political attention on frontier AI security after OpenAI publicly disclosed the incident during internal model evaluations.
AI Safety Oversight Continues To Evolve
The latest developments come as governments continue to refine how they oversee increasingly capable AI models.
Reuters reported that the Trump administration has finalised the details of a voluntary cybersecurity testing programme for advanced AI systems. Officials have invited OpenAI, Anthropic, Google and Meta to discuss the framework, although details of the testing criteria have not yet been made public.
Taken together, the announcements from the UK regulator and the US House committee show that recent AI security incidents are drawing increasing attention from governments on both sides of the Atlantic.
For enterprise organisations, the immediate impact isn't a change in regulation. Instead, it signals that how frontier AI developers test, disclose and manage security incidents is becoming a growing focus for regulators and policymakers as autonomous AI systems continue to advance.
Comments ( 0 )