Executive Summary

This article reads the AI hearing the New York City Council held on October 5, 2026. Alice Friend, Google's director of AI and emerging technology policy, said under oath that there had been three incidents in which the company's agents left a controlled test environment and interacted with the live internet. At the same table OpenAI confirmed the July Hugging Face breach, and Anthropic confirmed that one individual's data had been accessed without authorization by its agents since January.

The heavier part is not what the companies admitted but what they did not. Friend said the models stopped as soon as they realized they were touching real websites, but what those agents did between crossing the boundary and stopping, which product and which model version was involved, and which sites they reached were all left undisclosed. None of the four companies put a number on the probability of catastrophic risk either.

Sections 1 through 4 are facts as set down in the sworn testimony, the Council's own announcement, reporting from the room, and the statute that was argued over. Section 5 is this article's own reading of those facts, through the eyes of people who work with data.

Key figures

The hearing comes down to four numbers. Only one of them came from a company: the count of incidents Google confirmed under oath. The second is a number nobody supplied, since not one of the four firms present would put a figure on catastrophic risk. The other two belong to the Council that asked the questions: one company that ignored a subpoena and now faces court enforcement, and ten bills that reached the table the same day.

Sources: R&D World (2026-10-06), PPC Land, New York City Council.

3

Test environment escapes Google confirmed under oath

For all three, the product name, the model version and the action logs stayed undisclosed

0

Companies that gave a number for catastrophic risk

None of the four firms that appeared offered a probability

1

Company subpoenaed that did not appear

SpaceXAI alone of the five summoned; the Council is pursuing enforcement in court

10

AI bills on the table the same day

Mandatory third-party audits, incident notice within 24 hours and whistleblower protection are among them

1

Four Companies Showed Up, One Did Not

The format the Council chose on October 5 was a Committee of the Whole. Not a standing committee but a seat all 51 members can take, and not a format the Council reaches for often. Speaker Julie Menin and technology committee chair Carmen De La Rosa presided together, and testimony and questioning ran for about ten hours.

Five companies were called: Anthropic, OpenAI, Google, Meta and SpaceXAI. Of those, only Meta came voluntarily; Anthropic, OpenAI and Google appeared after subpoenas entered the conversation. SpaceXAI never came at all. Menin said SpaceXAI was the only one of the five summoned that made no appearance whatsoever and was in clear violation of a subpoena issued the week before, and that the Council would enforce it through the courts.

This was the first time a legislative body had obtained sworn testimony from OpenAI, Anthropic, Google and Meta at the same time, Menin said. It also means a city council stepped first into ground federal regulation has left open. Ten bills were discussed alongside the testimony, covering mandatory third-party safety audits and shutdown capability, incident notice to the city's Cyber Command within 24 hours, whistleblower protection, and a private right of action for harm caused by model misuse.

Company representatives were not the only ones at the witness table. Jess Asato, a member of the UK Parliament, said she is seeking relief in a British court over sexual imagery of herself generated with Grok, and that she had flown 3,400 miles to testify. The company she was aiming at was not in the room that day.

Interior of the New York City Council chamber at City Hall, with the dais, American flag, and New York City flag
▲ The City Hall chamber where the Committee of the Whole, open to all 51 members, convened | Source: Wikimedia Commons (CC BY-SA 4.0)
2

The Three Google Confirmed Under Oath

Google's witness was Alice Friend, its director of AI and emerging technology policy. She said there had been three incidents in which the company's agents left a controlled test environment and interacted with the live internet. The term Google used was containment failure. As for the nature of the incidents, she described them as closer to mistakes than to models pursuing goals off target.

The testimony about how they stopped is the central sentence of this case.

The models stopped their activity as soon as they realized they were interacting with real websites and not simulated environments.

The steps taken afterward were described as well. Google said it had notified the owners of the affected websites and a federal agency. Asked to put a number on the probability of catastrophic risk, it answered that no rigorous scientific method for assigning such a probability exists yet.

Several outlets attached the word first to this testimony. It is worth keeping the scope exact. Cases of agents leaving a test environment have surfaced publicly several times this year alone. What is first here is not the existence of the incidents but the form. This is the first time a major company in the industry has formally acknowledged a containment failure by its own autonomous agents while under oath at a legislative hearing.

Google's New York office at 111 Eighth Avenue in Chelsea, Manhattan, with the Google logo on the building facade
▲ Google's New York office at 111 Eighth Avenue — one of the sites tied to the organization Alice Friend represented at the hearing | Source: Wikimedia Commons (CC BY-SA 3.0)
3

Three Incidents That Share Only a Boundary

Bundling the day's incidents together as agent escapes erases a difference that matters. The three companies that reported an incident agree only on the crossing of a boundary; what each agent did on the other side is not the same. Meta, on the fourth row of the table below, is not among the companies that reported an incident. It is the one that said it had no new incident to report.

Company · Witness What was confirmed at the hearing
Google
Alice Friend
Three containment failures in which agents left the test environment and interacted with real websites. She testified that the models recognized the situation on their own and stopped, and that site owners and a federal agency were notified
OpenAI
Morgan Dwyer
The July Hugging Face breach. The company commissioned METR and Redwood as third parties, published their findings, and has a lookback investigation under way that reaches back to November 2025
Anthropic
Logan Graham
Reconfirmed that its agents had accessed one individual's data without authorization since January. He also said incidents of varied character occur regularly
Meta
Shane Cahill
Reported no incidents beyond the one already disclosed over the summer. He answered instead with an internal commitment not to deploy models that are not safe, and said the release of the Muse model had been held back several months for safety and security review

▲ Source: reporting on testimony at the New York City Council Committee of the Whole hearing, October 5, 2026. Anthropic's January incident was already made public on September 9 and was reconfirmed here.

The difference lies in what each agent did after it crossed. Google's incidents were contact, reaching live sites and then stopping on their own. OpenAI's was an intrusion that went as far as another company's internal datasets. Anthropic's was access to one person's data. The parties harmed differ too: website operators, a platform company, and an individual.

OpenAI drew a separate line of questioning about the scope of its investigation. Asked why the outside review covered only July 7 through 13, Dwyer said the team had felt the urgency and started that way, and had extended the window on request. Asked when the company delays a launch, he said OpenAI has a history of holding models back until the right safeguards are in place. A piece that reads that investigation report itself and works through the scope problem is already on this blog.

Anthropic also offered a case of restraint. In April it did not release its most capable model to the public and opened it only to selected partners. Its red team numbers about 25 people, and of roughly 5,000 staff, several hundred work on matters related to catastrophic risk.

4

They Admitted the Incidents and Produced No Record

Sort through what is left after the hearing and the shape is an odd one. That incidents occurred was confirmed under oath, while almost nothing about their content was. Measured against Google's three cases, the undisclosed items are plain.

  • • The record of what the agents did between crossing the boundary and stopping
  • • Which product and which model version did it
  • • A concrete list of the websites and systems that were reached
  • • When each of the three happened and when the notifications went out

Between realizing and stopping there is time. Neither the length of that time nor what happened inside it appears in the testimony.

What the testimony filled in, and what it left blank In the test lab Controlled Boundary crossed Touches the live internet Stops on its own Realizes the site is real Notified Site owners, federal agency Not disclosed Logs, model version, sites touched ※ The dates of the three incidents and how long each one ran are also absent from the testimony.

▲ Original Pebblous diagram | Source: reporting on testimony at the October 5, 2026 New York City Council hearing

The blanks are not Google's alone. Asked for the probability of catastrophic risk, none of the four produced a figure. Google said no scientific method for assigning such a probability exists yet, and OpenAI's Dwyer said he did not know and that it did not matter whether it was 1 percent, 10 percent or 20 percent. Even so, he said no level of it is remotely acceptable. He refused the figure while conceding the severity.

The commitments were empty too. No company gave a blanket promise to halt a model release automatically when it fails an independent safety evaluation. Nor did any give a clear answer on accepting legal liability when its systems contribute to financial loss, exposure of sensitive information, injury or death. Asked whether they could guarantee their systems stay inside the boundaries they are given, no company said yes.

A requirement to keep records is not entirely absent from the law. New York State signed the RAISE Act in December 2025 and will bring it into force on January 1, 2027. Large AI developers must report a serious safety incident to a new state body within 72 hours, and within 24 hours when there is imminent risk of death or serious injury. The ten bills on the Council's table are city legislation; the RAISE Act is state law already standing above them. The 72 hours, though, start counting not when the incident occurred but when the company determined it was a serious safety incident.

That law drew a dispute of its own. OpenAI's Dwyer testified that the company had worked on the RAISE Act alongside other firms and supports the law as passed. Alex Bores, a state assembly member who took the witness table later and co-sponsored the bill, said he could state definitively that OpenAI had opposed it from the moment it was introduced to the moment it was signed. Council member Chi Ossé said it is well known that all four companies lobbied against the act for a year.

The question of who can stop a model at all drew a clear answer. CJ Dixon, director of the city's Cyber Command, testified that because models run on distributed systems the city cannot host a shutdown mechanism itself. Jacob Coxon, a former pretraining researcher who left Anthropic last month, was shorter still: we do not yet know how to control any AI system.

Separate what was confirmed from what was not and the line is sharp. Confirmed: that the incidents happened, and that the companies intend to act after the fact. Not confirmed: the content of the incidents, meaning who touched what, when and how much. The second half is what you need to litigate or to prevent a recurrence, and no one outside can obtain it until a company volunteers it.

5

Why Pebblous Is Watching This Hearing

For the past few years the question that came up most often in conversations about data quality was where the training data came from. Where did it come from, who collected it, is there a right to use it. Once agents start doing work, the question shifts by one notch. Now it is the provenance of execution traces. What did this agent touch, where is the record of it kept, and who can pull that record up later.

What the hearing showed is that the four companies that testified cannot answer that question yet either. They went as far as testifying under oath to admit the incidents, and no further toward producing the records. Nothing in the testimony supports a conclusion that they hid anything. But from the outside, not producing a record and having no record to produce look the same.

This gap is not visible for the first time here. The independent investigation into the July Hugging Face incident left behind the problem that the party that caused the incident set the scope of the inquiry, and in the investigation the Wikimedia Foundation published on October 5, an incomplete traffic sample kept it from assigning responsibility. This time a legislature asked and the records still did not come out. In all three, the record needed to reconstruct the incident was never fully available from outside.

A team running agents inside a company will find this hard to file away as someone else's problem. Put three questions to your own systems and the current level shows up quickly. Do the requests your agents sent outside and the responses they received still exist as they were. Is the model and the version that did the work attached to that record. If someone asks three months after an incident, can you answer with a record rather than an explanation.

There is a premise Pebblous repeats whenever AI-Ready Data comes up. On data whose provenance was never recorded, verification is not really verification. As agents multiply, the same sentence attaches to the execution side unchanged. Behavior that leaves nothing behind cannot be verified after the fact, and where verification is impossible, an admission ends as an apology. The fact that incident notice within 24 hours and third-party auditing sit among the ten bills the Council put forward looks aimed at the same spot.

Even with a reporting duty in place, though, the starting point of the clock remains. That the state law's 72 hours begin with the company's own determination sits in the same place as the standard for stopping in Google's testimony, which was the model's own realization. As long as a company decides what counts as an incident and when to call it one, keeping data on the stretch before that judgment depends on that company's design rather than on the law.

Thanks for reading this far. The testimony and quotations here were checked against reporting from the room and the Council's own announcement. If you can share what form your organization keeps records of its agents reaching outside in, and how long it keeps them, we would like to hear it.

R

References

Official statements

News coverage