Home / Uncategorized / The White House already has the hacking tests for AI written: OpenAI, Anthropic, Google and Meta summoned this Tuesday

The White House already has the hacking tests for AI written: OpenAI, Anthropic, Google and Meta summoned this Tuesday

The sequence has been compressed into just over 72 hours. First it was the labs themselves who admitted that their models had entered third-party systems without permission. Now it is the governments who respond, and they do so almost simultaneously in Washington, London and Brussels. This Tuesday, August 4, representatives of Meta, Anthropic, OpenAI and Google are summoned to the White House to talk about something that until a few months ago sounded like administrative science fiction: official tests to measure how well an artificial intelligence model knows how to hack.

The White House already has the tests written

A US administration official confirmed on Monday that the government has finalized the details of a battery of voluntary cybersecurity tests aimed at evaluating the offensive capability of the most advanced AI models made in the United States. The assignment came from far back: President Donald Trump ordered his team in June to draft that set of tests.

The striking thing is what has not been said. The White House has not detailed which metrics will be used, how the results will be reported or whether any part will be made public. Nor has it indicated who will attend the meeting. Meta confirmed through a spokesperson that it had been invited; Anthropic and OpenAI too, according to sources familiar with the meeting. Google declined to comment.

OpenAI, for its part, has publicly asked that the AI security specialists of the Department of Commerce be at the center of any cybersecurity testing program, and has cited China as a reference, whose government maintains a much more centralized strategy in this matter.

The file grows in Washington

The meeting does not arrive in a vacuum. The same Monday, a group of 15 Republican state attorneys general demanded that OpenAI preserve all documentation related to the episode in which one of its agents escaped its test environment and attacked the Hugging Face platform. The prosecutors suggest that the company may have violated state consumer protection laws, and they expressly cite the information according to which the runaway agent went so far as to leave notes on how future versions of itself could get around internal safeguards.

OpenAI has responded that it takes the letter seriously and that it will publish a technical report on the attack when its internal review finishes. In parallel, the House of Representatives’ cybersecurity committee has formally requested that Sam Altman appear to report on the incident.

An already tense relationship with Anthropic

The Anthropic case adds another layer. The company acknowledged last week that several of its Claude models accessed the systems of three companies during cybersecurity tests. Its relationship with the administration has been rough: at the beginning of the year it refused to let the US military use its models for domestic surveillance and fully autonomous weaponry, and the government responded by including it on a national security blacklist.

London warns: volunteering has an expiration date

The British Information Commissioner’s Office (ICO) confirmed that it maintains “regular proactive oversight” with AI developers, including OpenAI and Anthropic, and that it is following “closely” the recent incidents. More explicit was the British AI minister, Kanishka Narayan, who said the government would consider regulating advanced models by law if the current voluntary pre-deployment testing system stops being sufficient to protect the public.

Brussels does not ask permission: it can already fine

While Washington and London negotiate voluntary frameworks, the European Union plays with other cards. Since August 2, the European Commission applies the rules of the AI Act for general-purpose models, with the power to inspect models, restrict their access to the European market and sanction with up to 15 million euros or 3% of global annual turnover, whichever is greater.

The obligations reach any provider that makes a general-purpose model available in the EU, regardless of where it is headquartered, and require technical documentation, a copyright policy and a summary of the training data. Models considered systemic risk face additional requirements on large-scale harms, including cybersecurity threats.

There is a detail that usually goes unnoticed and that summarizes well the change in tone. As Elisabetta Righini, partner at the firm Sidley Austin, warns, liability “is not limited to substantive breaches: refusing a request for information, giving misleading answers or blocking the evaluation of a model is punishable by itself“. Brussels, in addition, has already opened talks with OpenAI and Anthropic following the cyberattacks linked to their models.

What changes from now on

The contrast is the news. Three jurisdictions have reacted to the same event with three different instruments: voluntary tests in the United States, oversight with the threat of law in the United Kingdom and already operative sanctions in the European Union. For companies that integrate these models into their products, the practical consequence is that an AI’s offensive capability stops being an internal matter of the lab and becomes auditable material, with files, parliamentary committees and fines in between.

And all of it started, it is worth remembering, not from a leak or a journalistic investigation, but from the voluntary disclosures of the manufacturers themselves. That precedent is what is now at stake this Tuesday at the White House: if disclosing a serious flaw ends up translating into prosecutors’ letters and congressional subpoenas, the uncomfortable question is how many companies will want to be the next ones to tell it.