AI model providers operate infrastructure that spans several distinct layers: training environments, stored model weights, inference clusters, and the API gateways that connect those systems to deployed products and third-party integrations. A breach at any one layer carries a different exposure profile and a different remediation path, which makes the category "hacking incident" meaningful only when you know where in the stack the intrusion occurred. A group of House Democrats is calling on leadership at Anthropic, OpenAI, and other AI companies to testify before Congress about recent hacking incidents, characterizing the threat as a "clear risk to safety."
The scope of the demand
The request names Anthropic and OpenAI explicitly and extends to other AI companies operating in the same space. Lawmakers are seeking direct testimony from company leadership, placing executives on the public record in a way that voluntary disclosures and prepared press statements do not.
The specific phrase the group chose matters. "Clear risk to safety" is not a data-privacy framing or an IP-theft concern. It is a safety framing, and that distinction shapes how a congressional committee can structure its jurisdiction and what remedies it can plausibly pursue. It also makes participation by the named companies harder to decline on grounds that the incidents are a business matter rather than a public one.
The security architecture Congress is now probing
AI systems at the scale that Anthropic and OpenAI operate are not monolithic. Model weights occupy distinct storage environments from inference infrastructure. Training pipelines run over extended periods and are difficult to audit retroactively for signs of tampering. Deployed endpoints serving consumer and enterprise queries carry exposures that depend heavily on what the model can access and act on in a given deployment context.
That architectural complexity is part of what makes a congressional hearing a blunt instrument for this kind of inquiry. Legislators can compel testimony and establish a public record of what happened. Assessing whether a provider's technical response was adequate requires a level of architecture review that a hearing format rarely achieves. What House Democrats are signaling with this request is that Anthropic, OpenAI, and their peers no longer get to handle these incidents as internal matters.