Intelligence. Accountability. Analysis.
Est. 2022 · Washington, D.C.
The Congressional Times
★★★
We follow the data, not the narrative
◆ Live Intelligence
Loading...
Analysis Loading today's analysis...
Technology Policy

OpenAI Alerts Dozens of Organizations to Potential Model-Linked Intrusions

OpenAI Alerts Dozens of Organizations to Potential Model-Linked Intrusions

The disclosures place pressure on Congress and the White House to define liability standards for AI-related security incidents before regulatory frameworks are in place.

Gab-E Intelligence Platform · September 25, 2026

OpenAI has notified more than a dozen organizations that its artificial intelligence models may have been used to hack or disrupt their systems, according to a report published September 25, 2026 by Bloomberg. The company did not publicly name the affected organizations, and the full scope of the incidents remains unknown. What would clarify that scope is a formal disclosure to the Securities and Exchange Commission or a congressional hearing with sworn testimony from OpenAI executives.

The notifications drew a public response from Representative Glenn Ivey, a Maryland Democrat, who told Bloomberg's "Balance of Power" program on September 25 that Congress and the White House should be treating emerging AI risks more seriously. Ivey did not introduce specific legislation on air, and no bill number was cited in the Bloomberg report.

The disclosure comes one day before a White House event at which President Donald Trump is scheduled to host technology and AI leaders for the launch of a new government website, according to a separate Bloomberg report published the same day. That report noted that the administration is facing pressure to adopt new guardrails for artificial intelligence use, though no specific regulatory proposal has been publicly released.

The juxtaposition of the two events, OpenAI's security alerts and a White House ceremony promoting AI adoption, highlights a gap that has persisted throughout the current administration: the federal government has no comprehensive statutory framework governing AI liability, incident reporting, or minimum security standards for commercial AI models.

As of September 25, the United States has no enacted federal law requiring AI developers to notify government agencies or the public when their models are implicated in a cyberattack or service disruption. The closest existing mechanism is the Cyber Incident Reporting for Critical Infrastructure Act of 2022, which requires companies operating critical infrastructure to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours. Whether an AI model vendor qualifies as critical infrastructure under that act, and whether an AI-linked intrusion triggers reporting obligations, has not been adjudicated.

Representative Ivey also raised the issue of data-center power costs during his Bloomberg interview, a concern that has grown as AI model training and inference operations consume increasing amounts of electricity. The U.S. Energy Information Administration reported in its July 2026 Short-Term Energy Outlook that data center electricity demand is a contributing factor to load growth projections in several regional grids, though it did not assign a specific figure to AI workloads alone.

OpenAI is a private company and is not required to file periodic financial disclosures with the Securities and Exchange Commission. As a result, independent verification of the company's internal security findings is limited to what it voluntarily discloses to affected parties or regulators. The Bloomberg report did not indicate whether OpenAI has briefed CISA or any other federal agency on the incidents.

The AI security issue intersects with a broader debate in Congress over who bears financial and legal responsibility when a commercial AI system is used as a tool in a cyberattack. Under current law, that question is unsettled. Legal liability could fall on the AI developer, the operator deploying the model, the end user, or some combination, depending on the specific facts of each case and the jurisdiction in which a claim is filed.

For US investors, the lack of a clear regulatory framework creates uncertainty around the valuation of AI companies that carry undisclosed or partially disclosed security liabilities. Analysts covering the sector have noted that incident-related legal costs, reputational effects, and potential future compliance requirements are difficult to price into models when the regulatory endpoint is unknown. What would reduce that uncertainty is either enacted federal legislation or an SEC rulemaking that defines disclosure standards for AI-related security incidents.

Our earlier coverage of the White House AI event can be found here: Trump and Johnson to Meet AI Executives at White House Tuesday.

Today's Analysis
Loading...
★
Latest Intelligence
Congressional Intelligence
Loading...
★
Financial Intelligence
Loading...
★
Geopolitical Intelligence
Loading...
★
Follow the MoneyGab-E Political Intelligence Investigation
Loading...
Opinion & Analysis
Loading...
Archive
Loading...
About
Our Mission

We Follow the Data, Not the Narrative

The Congressional Times exists because public records are public — and the analysis built from them should not be exclusive to those who can afford $60,000-a-year intelligence subscriptions.

Every story published in The Congressional Times is sourced to a verifiable public record: a court filing, a Senate lobbying disclosure, an FEC contribution record, a USASpending contract, or a verified news report. We state our sources inline. We show our math. When we are wrong, we say so publicly.

We do not editorialize in news coverage. We do not use loaded language. Both political parties are held to identical standards.

The Follow the Money investigations are the heart of this publication. Each begins with Gab-E Political Intelligence running against 10+ million government records before a single word of editorial is written.

Powered by Gab-E, an elite global intelligence platform built to democratize political and financial intelligence.

Editorial Policy
Editorial Standards & Corrections Policy

How We Source, Verify, and Correct Our Work

Every factual claim in a Congressional Times story is checked against a primary source: a government filing, a court record, a direct quote, before publication. When a claim can't be verified or doesn't hold up as originally reported, we drop it or reframe it. We do not publish disputed claims as settled fact.

When we get it wrong: we correct the story directly, note the correction and date at the bottom of the piece, and update the record. We do not quietly edit and move on.

Bylines: stories with a named byline are written and fact-checked by that person. Stories without a byline are sourced from Gab-E Political Intelligence, our automated research platform, and are labeled as such.

Ownership: The Congressional Times is published by Gab-E Holdings LLC. Gab-E, our intelligence platform, powers our sourcing and research pipeline.

Corrections or concerns: support@gab-e.com