On 2 September, Representative Greg Casar published his follow-up correspondence with OpenAI and Anthropic about major cybersecurity incidents, along with both companies' replies. The coverage that followed turned it into a story about OpenAI building an automated shutdown capability. The sharper material in the release is directed at the other company.

What the letter says

Casar's language, quoted in his own press release, is unusually blunt for follow-up correspondence: "Your response was insufficient. You failed to release the logs like the letter asked. You failed to fully answer a majority of the questions posed in the letter." He then names the specific omission — the response "did not address our question about how many times in the past year an internally deployed" model was involved in an incident — and concludes that the company is "not treating these cybersecurity incidents with the seriousness required." He asks both companies to respond by 15 September.

Two letters, one narrative

Casar sent follow-ups to both labs and posted both, together with each company's response letter. The reporting cycle picked the disclosure that made the better headline — OpenAI describing work on automated shutdown for its tools — and largely dropped the second track. On the measure the office itself applied, answering the questions asked, the record published on 2 September is worse for Anthropic than for OpenAI.

What the common framing gets wrong

A congressional follow-up letter is not an investigation, a subpoena or a finding. Nothing here compels production of the logs; a member of the minority asking again, in public, with a date attached, is the whole of the mechanism. Treating the 15 September deadline as an enforcement milestone overstates it. The correct read is narrower and still notable: both frontier labs were asked for incident logs, both declined to provide them, and one of the two also left most of the substantive questions unanswered.

The question nobody answered

The unanswered item is the one worth tracking. How often an internally deployed model has been implicated in a security incident at the lab that built it is not a disclosure any frontier developer currently makes, in a filing, a system card or a transparency report. It is also the question that separates published safety evaluation from operational reality. Both companies have until 15 September to say whether they will answer it.