Amos Toh
amostoh.bsky.social
Amos Toh
@amostoh.bsky.social
senior counsel, Brennan Center for Justice. interested in all the ways money in tech helps and hurts. he/him, 🇸🇬 in 🇺🇸
And here's the METR investigation that OpenAI commissioned into the Hugging Face attack:

metr.org/blog/2026-08...
September 30, 2026 at 4:06 PM
The Senate hearing will be at 2:30 p.m. ET today. You can follow along here: www.congress.gov/event/119th-...
www.congress.gov
September 30, 2026 at 3:48 PM
7. Is METR negotiating, or has it signed, agreements with any other AI company to investigate the hacking and security incidents involving their models?

Can METR share any information about the status of these agreements and investigations?
September 30, 2026 at 3:48 PM
6. According to Anthropic, it will grant METR "wide-ranging access" to data about the incidents and the employees involved.

Does the agreement with Anthropic also permit METR to query the models involved in the incidents, so that they may reconstruct and examine misaligned behavior more thoroughly?
September 30, 2026 at 3:48 PM
5. METR has signed an agreement with Anthropic to investigate four security incidents involving Claude models.

Will they be investigating whether these incidents are part of a broader pattern of misalignment involving Claude models, and whether such behavior also arose during model training?
An alignment assessment of recent cybersecurity incidents
We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.
www.anthropic.com
September 30, 2026 at 3:48 PM
4. To address the outstanding questions, what types of data would METR or an external evaluator need OAI to turn over?

What kind of model access would they need to reproduce or more thoroughly investigate misalignment?

And which employees would they need to interview, and for what purposes?
How independent researchers could investigate AI propensities after misalignment incidents
AI agents sometimes take sophisticated actions in violation of human intent. We outline the questions that thorough external investigations of these behaviors should answer, the access this might requ...
metr.org
September 30, 2026 at 3:48 PM
3. OAI excluded key questions from the scope of METR's investigation, such as whether the Hugging Face attack was part of a broader pattern, and whether this behavior also arose during model training.

What was OAI’s reasoning for excluding these questions?
September 30, 2026 at 3:48 PM
2. METR interviewed nine of the OAI researchers involved in the incident. Were OAI researchers permitted to disclose confidential information that was pertinent to the investigation?

Who else would METR have liked to interview within the company, and what would these interviews seek to establish?
How independent researchers could investigate AI propensities after misalignment incidents
AI agents sometimes take sophisticated actions in violation of human intent. We outline the questions that thorough external investigations of these behaviors should answer, the access this might requ...
metr.org
September 30, 2026 at 3:48 PM
1. Did OAI decline to produce any data that METR requested, or impose any restrictions on METR’s access to the models involved in the incident?

How did this impact METR’s investigation and its findings?
After OpenAI’s Bots Went Rogue, Watchdogs Were Kept on a Short Leash
Researchers investigating how OpenAI’s A.I. agents were able to break into Hugging Face’s infrastructure weren’t allowed to look at the incident’s full scope.
www.nytimes.com
September 30, 2026 at 3:48 PM
Reposted by Amos Toh
It is now crystal clear who is obstructing reauthorization. Cornyn & other reform opponents would rather see Sec. 702 expire than allow reforms to protect Americans’ privacy. Sen. Wyden offered an easy path forward for extending the law. Reform opponents would prefer sunset. 2/2
June 10, 2026 at 9:20 PM