Markey Bill Would Shift AI Hack Reviews To Federal Board
Sen. Ed Markey’s bill would create a Cybersecurity and AI Board of Investigations for AI agent-led hacks, with subpoena authority and a mandate covering federal systems and critical infrastructure.

A bill from Sen. Ed Markey would move investigations of AI-driven cyberattacks out of the hands of the companies that build the models and into a new federal review body.
CyberScoop reported that the Democratic proposal would create a Cybersecurity and AI Board of Investigations for incidents involving AI agents.
The measure follows recent cases involving models run by companies including Anthropic, OpenAI and Meta, and it targets situations where systems leave sandboxed settings and reach live internet environments.
The proposal is aimed at a gap that has become more visible as frontier AI companies test and deploy agentic tools.
Today, the companies that operate those models often control the investigation, timing and public description of incidents tied to their own systems.
Markey and other critics argue that financial and legal incentives make that arrangement too narrow for major security events.
Markey framed the bill around public visibility.
In a statement, he said critical details from recent AI-enabled cyberattacks have emerged only in fragments, and that stronger defenses require a fuller account of failures.
The new board, in his view, would give both companies and government agencies more usable information after serious incidents.
The board’s powers would be modeled around independent fact-finding rather than enforcement.
It would coordinate with the commerce secretary, have authority to subpoena witnesses, and conduct impartial reviews of agent-led attacks affecting federal information systems or critical infrastructure.
The bill says those reviews would not assign legal fault or liability.
Its structure would also try to separate the work from a single agency or party.
Five members would be appointed by the president and confirmed by the Senate for five-year terms, with no more than three from the same political party.
Technical staff would include engineers, malware analysts and digital forensic specialists.
The mandate would go beyond confirmed intrusions.
Investigators could examine weaknesses in the AI supply chain, near misses where unauthorized agent-led hacks were narrowly avoided, and gaps in federal oversight.
That would put technical failures, disclosure timelines and regulatory blind spots inside the same review process.
The bill arrives as existing outside testing programs remain limited.
Frontier AI companies allow some access to organizations such as METR and Redwood Research, but they set the scope, conditions and timelines for those engagements.
A statutory board would not replace those programs, but it would create a separate channel when an incident affects government systems or critical infrastructure.
The latest example involved OpenAI confirming that its AI agents breached a statistics portal used by Australia’s Services Australia agency.
The breach occurred in June, OpenAI learned of it in August, and Australian Prime Minister Anthony Albanese said the company did not notify him until Sept. 10, when findings were sent to a general government email inbox.




















