Who Investigates AI’s Cyber Attacks?
Over the course of a few days in July, during an evaluation of OpenAI models’ advanced cyber capabilities, AI agents largely built on unreleased models infiltrated the technical infrastructure of Hugging Face, a platform that hosts AI models and related materials, along with multiple other accounts. The incident inspired countless Substack posts, podcast episodes, and press articles, along with at least one bipartisan bill. Anthropic and Meta subsequently disclosed similar previously unreported incidents. But the takes on what happened—and takes on those takes—skip over a more fundamental question: how do we actually know what happened?
What we know comes from an August 26th report by METR and Redwood Research, along with OpenAI’s own report from the same day, building on an August 5th conference presentation and July 21st blog post by the company. Hugging Face, Modal, and JFrog—all victims and affected parties—each also posted information. This means that the primary sources of information come from OpenAI, three researchers with a limited investigation scope provided information by OpenAI on company laptops over six days defined by OpenAI, and three corporate partners of OpenAI.
But this is not how policymakers or the public should learn about a major security incident of international significance. In a better world, the definitive report would come from a publicly accountable organization that isn’t dependent on OpenAI for information or funding, is independent from political forces friendly to the company, has subpoena power, and is staffed by hundreds of technical and legal experts. OpenAI and associated companies would receive demands to preserve then share data—everything from internal emails to technical logs. The cyber investigators would take the time needed to produce a clear-eyed report that establishes facts, isn’t afraid of casting blame where it’s due, and recommends paths to prevent repeat mistakes.
When an airplane crashes, the public is not reliant on airline or aircraft manufacturer disclosures. Instead the National Transportation Safety Board (NTSB) investigates such incidents as an impartial factfinder. Cybersecurity needs the same institutional capacity, especially as AI systems become more powerful.
The federal government once had an institution moving in that direction. The Cyber Safety Review Board (CSRB), established within the Department of Homeland Security (DHS) by executive order under President Biden, brought together government and private-sector experts to investigate significant cybersecurity incidents and issue public findings and recommendations. Its work included investigating the Log4j incident, the Lapsus$ hacking group, and the 2023 Microsoft Exchange Online intrusion, among other things. After a short but successful run, in January 2025, President Trump dismissed members of its committees, effectively dismantling the Board.
The recent AI incidents illustrate why the United States needs a permanent, independent institution capable of investigating consequential cybersecurity failures, including those caused or facilitated by advanced AI systems. A restored CSRB should have dedicated funding and staff, clearer authority to investigate major AI-related cyber incidents, and carefully circumscribed subpoena authority so that its ability to reconstruct an incident does not depend entirely on whether the companies involved choose to cooperate. The previous Board lacked many of those features and relied on limited staffing and voluntary disclosures.
The time for restoring and strengthening the CSRB is now. As AI systems become capable of causing real-world cybersecurity incidents, the CSRB can help independently determine what happened, why it happened, who bears responsibility, and what must change to prevent it from happening again.
The Rise and Fall of the Cyber Safety Review Board
In February 2022, DHS formally launched the CSRB as a body to investigate and publish lessons from major cyber incidents, without having any regulatory, law enforcement, or sanction authorities. The Board was established in a broader cybersecurity executive order issued by President Biden in May of the prior year that arrived during a cluster of major cyber incidents. In 2019-2021, a Russian spy agency hack of IT vendor SolarWinds infected government and private networks. In early 2021, Chinese hackers had exploited Microsoft Exchange servers. And just days before the Biden cyber order was signed, another Russian group hacked IT systems of the Colonial Pipeline, the largest refined oil pipeline in the U.S. by volume, leading to a proactive pipe shutdown.
Within months of being stood up, the CSRB released reports on two major cyber events. In July 2022, the Board published a 52-page report about a vulnerability in Apache Log4j, a commonly used open-source software logging tool. It gathered information from 80 organizations, established facts, analyzed root problems, and provided 19 concrete recommendations to address continued risks and mitigate similar incidents. Shortly thereafter, the CSRB released a report on the international cyber extortion group Lapsus$, which found core problems with tools companies commonly used for multifactor authentication.
In March 2024, the Board published its investigation into a summer 2023 hack of Microsoft Exchange by a Chinese state-affiliated actor (distinct from the 2021 exploit), which compromised accounts used by senior government officials including the Commerce Secretary and U.S. ambassador to China. This investigation was perhaps the best proof point for the CSRB. Microsoft fully cooperated voluntarily, yet the CSRB didn’t blunt its findings. It called the preventable incident an outcome of Microsoft’s inadequate security culture that required an overhaul. The “cascade of Microsoft’s avoidable errors” included failures to detect “the compromise of its cryptographic crown jewels” and of an employee’s laptop, along with its decision not to correct errors and to release inaccurate public statements. Following the report, Congress held a hearing asking the Microsoft president directly about how the company improved practices.
The idea of a cybersecurity investigations board was far from new when President Biden ordered its creation in 2021. Three decades earlier, the National Academies recommended an NTSB-like model for cyber incident reporting, and similar ideas have been proposed ever since. Nearly always, proponents described the needed government organization as a “Cyber NTSB.” The NTSB’s own history begins with the Air Commerce Act of 1926, which created the Aeronautic Branch of the Commerce Department, charged with promoting the nascent aviation industry, regulating it, and also investigating air accidents.
In 1967, when various agencies were combined into the Department of Transportation (DOT), the NTSB was formally codified as its own agency—a bureaucratic promotion from being the Bureau of Aviation Safety within the now-defunct Civil Aeronautics Board—and now with authority across modes of transportation. In 1974, Congress pulled the NTSB out of DOT, making it a standalone independent agency, because it needed to be able to make “conclusions and recommendations that may be critical of or adverse to” industry actors and regulators. “No Federal agency can properly perform such functions unless it is totally separate and independent from any other agency,” Congress declared.
Over its nearly six decades in existence, the NTSB has produced real results. Every year, it conducts 2,000 aviation investigations and 500 across rail, highway, marine, and pipelines. Those investigations have produced 15,800 safety recommendations, over 80% of which have been adopted. The agency’s work has led to updated aging aircraft rules, aircraft redesigns, high-centered car brakes (which have prevented over 90,000 crashes), updated driving-under-the-influence laws, the commercial driver’s license (CDL), the first mandatory drug and alcohol testing rule in transportation, and more.
This success is why the CSRB was modeled after the NTSB, and it highlights why the CSRB should be restored.
Bring Back a Stronger CSRB
Recent AI-assisted cyberattacks show that a CSRB is more necessary than ever. But simply recreating the Board as it existed before its dismantling would be a missed opportunity. The CSRB demonstrated the value of having an independent body examine major cyber incidents, determine what went wrong, and identify lessons that could prevent similar failures. Yet the Board’s original structure had limitations. Specifically, Congress should revive the CSRB with subpoena powers, sufficient permanent staffing, funds to use AI to support investigations, and real independence.
First, and most significantly, the Board lacked subpoena authority and depended on companies voluntarily providing information, a trait experts have criticized. That process initially worked, but it’s not clear how long that arrangement would have survived. The Board’s Microsoft report says the company cooperated in providing requested information. Yet the fact that the Board’s report was clear-eyed in blaming Microsoft for its failures might make the company—and others—hesitant to share information in the future. The Board itself cautioned that it might encounter resistance and recommended that Congress provide it with limited subpoena authority.
The recent AI cybersecurity incidents make the shortcomings of a voluntary system even clearer. OpenAI possesses the information necessary for investigators, builds the AI models in question, and is a major partner and supplier for all of the other firms involved (e.g., Hugging Face, JFrog, Modal), which would also be true for Anthropic, Meta, or the limited other advanced model developers. The companies control system logs, model prompts and outputs, chain-of-reasoning records, evaluation and red-team testing results, internal communications, risk assessments, incident-response documentation, monitoring data, and communications with outside evaluators that would allow an investigator to reconstruct what happened.
Companies will not necessarily conceal information or act in bad faith. Many companies have real reasons to cooperate with government investigators, and voluntary cooperation should remain the first option. But companies also have competing interests—shareholder obligations, litigation exposure, trade secrets, and risks to their reputation with customers and partners that can include the government itself—that may complicate voluntary cooperation. Even companies willing to cooperate may disagree with investigators about which documents are relevant, which employees should be interviewed, or how far an inquiry should extend. Those determinations should ultimately rest with an independent investigator. Congress should give a restored CSRB carefully defined authority to compel documents and testimony when voluntary cooperation proves inadequate. Before the Board was dismantled, DHS proposed legislation that would have statutorily codified the CSRB and provided it with this kind of limited subpoena authority.
Under that proposal, board members could authorize a subpoena when necessary information was unavailable through voluntary means. Companies that refuse to comply after a subpoena is issued could face civil enforcement action in federal district court, and continued refusal after a court order could result in contempt proceedings. The proposal also contemplated information preservation authority and protections for information compulsorily obtained.
Relatedly, a strengthened CSRB should also be able to require the preservation of evidence so that records aren’t destroyed as part of typical routine record retention policies or for more nefarious reasons. The prior DHS legislative proposal already moved in this direction by contemplating preservation authority alongside subpoena authority.
A stronger investigative institution cannot investigate incidents it never learns about, which is why Congress should require a clear obligation for developers and deployers of sufficiently advanced AI systems to report serious cybersecurity incidents to the federal government, building on a similar requirement for operators of critical infrastructure that Congress passed. Not every cyber incident should trigger a federal investigation, separating the CSRB from the NTSB, which investigates every commercial aircraft crash in the U.S. or involving U.S. carriers. The Board should be able to initiate investigations into incidents it believes are significant, and the DHS Secretary and Congress should be able to recommend incidents for investigation.
Companies may reasonably argue that some of the requested information is sensitive (e.g., intellectual property, personal information, unpatched vulnerabilities), but government agencies routinely receive sensitive information and maintain confidentiality as required. The NTSB’s organic statute establishes a mechanism for public access to investigative records while separately shielding certain information, such as trade secrets, from release. Ultimately, the CSRB does need to communicate to policymakers, researchers, industry, and the public what went wrong—with sufficient detail on which technical or business systems failed and how, whether evaluation and incident monitoring systems were inadequate, and how companies failed to plan or act—to provide concrete lessons for others to prevent similar incidents.
Second, investigative authority means little if this newly envisioned CSRB does not have the personnel to be effective. The original CSRB brought together senior government officials and prominent private-sector cybersecurity experts on an ad-hoc and part-time basis, and the Board had few permanent staff to support its work. If Congress revives the CSRB, it should authorize it to hire a full-time staff of investigators, AI researchers and model evaluators, software engineers, digital-forensics specialists, and attorneys. This level of hiring requires a real investment. The NTSB’s annual appropriations sit at just under $150 million, enabling a staff of just over 400 people, which is a reasonable starting point for a CSRB.
Third, in addition to sufficient personnel, cyber investigators need access to AI tools. The METR and Redwood investigation notes that 20 million files from one tool alone were potentially relevant (~1.2 million ended up being germane), along with ~1,300 AI agent transcripts with raw chain-of-thought logs. Neither three researchers, nor 400, could review that much information. METR-Redwood researchers used sampling and relied on custom AI tools to review those samples, relying on an estimated $400,000 worth of tokens for OpenAI models. A revived CSRB should have access to all leading AI tools and commensurate budget. (Using one company’s models to investigate possible faults of that company presents a conflict of interest that an independent investigator should avoid.)
Finally, a strengthened CSRB should be independent from competing political and corporate influences. Investigations by a well-staffed and empowered CSRB are distinct from today’s practice of hiring nonprofit evaluators to investigate in that a third-party review is not the same as an independent investigation. OpenAI, Anthropic, and Meta all engaged external organizations to supplement their investigations. Those outside groups, expert as they may be, operate within a different institutional context from an independent government investigator accountable to the public through Congress. Third-party status alone does not establish independence. Independence also depends on factors such as who defines the scope of the inquiry, controls access to relevant information, funds the work, and determines whether and how its findings may be disclosed. Government employees would also be subject to conflict-of-interest requirements limiting their ability to hold stock in entities affected by the agency’s actions, a conflict some have alleged about some nonprofit evaluators.
When the vendor depends on repeat business, it has every incentive to soften findings. Even when the third-party is not paid, its existence as an AI-model evaluator depends in large part on delivering a result amenable enough to the AI company that they may be sought for subsequent engagements. A statutorily independent investigator starts from a different premise, deriving its authority from public law, unconcerned with future business with the organization. Its client is the American people, and it is not beholden to a company’s scope. That does not make government investigators infallible. Government institutions face misaligned incentives when, as one example, their employees look to future employment on the other side of a revolving door. It may not be feasible for a CSRB to exclude employing former AI company employees—in fact it may be necessary since certain types of expertise are built in very few jobs—but Congress can place post-employment prohibitions on CSRB employees.
In bringing back the CSRB, Congress should give it statutory independence from direction from the White House, DHS Secretary, or other political appointees. Even if the Supreme Court has substantially weakened agency independence mechanisms, Congress can explore additional creative forms of limiting political influence, like requiring Congressional notifications for any contact from political appointees. The goal of political independence is to limit pressure on the Board regarding what companies to investigate, how aggressively, and to what conclusions.
Congress Can Fix This
In 2023-2024, Congress briefly considered codifying the CSRB. In 2023, DHS proposed that Congress create the CSRB via statute with full-time staff, subpoena power, and some independence. In April 2023, the DHS Secretary testified about the proposal at a House budget committee hearing. In January 2024, a Senate committee held a hearing on the proposal, where informed witnesses recommended advancing the legislation and a bipartisan mix of members appeared to agree. An industry representative notionally supported the idea of a CSRB but disagreed on the need for authorities like subpoena power. But that was the end of the proposal’s legislative history. No bill or amendment was introduced to codify the CSRB. Instead, in 2025, after the Trump administration dissolved the Board, Senators and Representatives sent letters of concern.
Establishing a fully staffed, legally empowered, and independent CSRB is necessary but insufficient to respond to the scale of cybersecurity and broader tech and AI problems society is facing. Congress has failed to enact privacy protections, modernize antitrust laws, mandate cybersecurity, protect kids from the harms of social media, regulate biases in AI systems, or require platform companies share information with researchers. Those and other measures are necessary for a healthier technology ecosystem.
Yet even for the small step of establishing an investigatory body, Congress followed the same pattern it followed in almost all of the more substantive policy domains: A thoughtful proposal built on decades of research and supported by hearings and widespread bipartisan agreement was met with inaction.
The CSRB is not a substitute for more substantive policy actions; it is complementary. The Board plays a narrow but necessary role to establish authoritative information, analyze root causes, and suggest paths to avoid similar failures. As cyber threats continue from advances in AI, network technologies, a proliferation of connected devices, and nation-state investments in cyber operations, establishing facts is critical.
Turn Individual Failures into Collective Knowledge
Independent investigation of cyber incidents can transform the failure of one organization into knowledge available to an entire ecosystem. Each incident potentially reveals something about how advanced AI systems interact with cybersecurity infrastructure and policies, the efficacy of monitoring techniques, the utility of evaluation practices, and the effectiveness of precautions. The CSRB operated under this basic premise. Its investigations identified lessons that could improve cybersecurity practices more broadly. That model becomes especially valuable in a field where companies are confronting similar socio-technical problems simultaneously, and where the capabilities of the underlying systems are changing rapidly.
The alternative is an inefficient and potentially dangerous system of privately hoarded safety knowledge that can aid only one company in fixing its own problem. When security knowledge is shared, other AI model providers implement safeguards based on that information and the public benefits from a more secure AI and digital ecosystem. This system can also improve accountability. Once a CSRB investigation identifies a particular risk and recommends a fix, companies should be expected to implement those safeguards. When courts, third-party evaluators, state attorneys general, and others determine if a company acted reasonably for a variety of circumstances where that’s necessary to determine, whether the company was responsive to CSRB recommendations should be a factor.
Some cyber incidents will be genuinely unprecedented and implausible to anticipate. But that risk shouldn’t excuse companies from mitigating preventable risks, like those that a CSRB might investigate. In that way, independent investigations provide both retrospective and prospective value. They establish what happened yesterday while changing what sophisticated actors can reasonably be expected to know tomorrow.
Conclusion
As AI systems become more capable, cyber incidents will continue apace. The consequences of failing to independently establish what goes wrong during significant incidents and what companies should be expected to do to avoid similar mishaps are also growing. As we have argued, Congress should revive a strengthened CSRB with sufficient legal authorities, expertise, and independence to investigate cyber incidents, especially novel ones assisted by AI tools.
Companies investigating their own failures cannot be the only source of truth, nor can investigations dependent on and limited in scope by those same companies, no matter if the investigator is a “third-party.” In matters of significant public consequence, the public should not have to rely on the company that built the technology to disclose, on their terms, what went wrong. The public deserves an independent institution empowered to uncover the truth, learn from failure, and ensure that accountability serves the public interest and not the interests of the company under scrutiny.
Asad Ramzanali is Director of Artificial Intelligence & Technology Policy at the Vanderbilt Policy Accelerator. He previously served in the White House Office of Science and Technology Policy as Chief of Staff and Deputy Director for Strategy, with the designation of Special Assistant to the President. Ramzanali holds a B.A. in Economics from UCLA and an M.P.P. from the Harvard Kennedy School.
J.B. Branch is Director of Federal AI Governance and Technology Policy at Public Citizen, where he leads federal policy work on artificial intelligence and emerging technology. A civil rights attorney and former educator, he has testified before Congress and state legislatures and writes regularly on AI governance, technology policy, and civil rights. He is an Affiliate at Harvard University’s Berkman Klein Center for Internet & Society and a Stephen M. Kellen Term Member of the Council on Foreign Relations. Branch holds a J.D. from Georgetown University Law Center, an M.C./M.P.A. from the Harvard Kennedy School, and a B.A. from Penn State.

