Rules & Policy · Oct 6, 2026
AI labs testify under oath at New York City Council; Anthropic says it withheld Mythos from public release over its ability to write attack code, while SpaceXAI ignored a subpoena and the council will ask a court to compel it
Frontier labs reportedly put their reasons for not releasing a model on the record, under oath, in a municipal forum for the first time. Whether the council can force the one company that stayed away to appear will decide how far local AI oversight can reach
Koji Yamamoto · Economics Analyst

Key points
- OpenAI, Anthropic, Google and Meta reportedly testified under oath at a New York City Council hearing on October 5. It is said to be the first time frontier labs have given sworn testimony before a municipal body
- Anthropic reportedly said it did not release Claude Mythos to the public because of the model's ability to write attack code. This puts a lab's reason for withholding a model into a sworn record for the first time
- SpaceXAI reportedly did not respond to its subpoena, and the council will ask a court to compel it to appear. The outcome of that motion will decide how far a city can extend oversight to frontier labs based outside the state
Representatives of OpenAI, Anthropic, Google and Meta testified under oath at a New York City Council hearing on AI oversight held on October 5, according to CBS New York, Hell Gate, Yahoo News and other outlets. It is said to be the first time frontier labs have given sworn testimony before a municipal legislature. Anthropic's account has drawn the most attention. According to the reports, Anthropic said it did not release Claude Mythos to the public because the model can write attack code. SpaceXAI, meanwhile, reportedly did not respond to its subpoena, and the council is said to be preparing to ask a court to compel it to appear. The testimony is now on the record. The next question is what a city can do about the one company that did not show up.
This article is based on media reports. We have not been able to review the council's official transcript or the original text of the companies' testimony. Witness names, exact wording of statements, and the filing date and court for the motion are included only where we could confirm them.
The reason for not releasing is now in the sworn record
Until now, when labs held back a release, their explanations reached the public through company blog posts, system cards, or news reports citing anonymous sources. What is different this time is that the explanation was reportedly given in a legislative setting, under oath. The record now carries potential legal liability for false statements, which makes it harder to revise the account later.
According to the reports, Anthropic cited the model's ability to write attack code to explain why it has kept Mythos from the general public and provided it only to a limited set of defenders. That explanation fits with events of recent weeks. Mythos and Project Glasswing have found 286 CVEs. On October 3, The Register reported that one of them, an authentication bypass flaw in Rejetto HFS (CVE-2026-61500), was being exploited by the day after it was disclosed (previously reported). The case shows how quickly a flaw found by AI can be turned into an attack, and it supports the view that opening this capability to the public carries serious consequences.
Limiting access to frontier models on cybersecurity grounds has become an established practice across the industry. Google released Gemini 4 Argon through its Fairwind Program, which is restricted to cyber defense professionals. OpenAI rated GPT-6.1 Sol as Critical for cybersecurity and called off the release of GPT-6.1 Astra (both previously reported). Until now, companies made these decisions on their own and explained them in their own words. This time, the explanation has entered a city's official record.
Not only the labs took the stand
According to 1010 WINS (Audacy), a former Anthropic researcher also testified. WSLS, apparently carrying an AP report, said industry insiders had sounded an alarm to the council, and placed the hearing within a broader trend of local governments taking up AI safety. The reports suggest the council sought to put the labs' official accounts and an insider view from a former employee into the same record. We have not, however, been able to confirm the former researcher's name or the details of their remarks.
The hearing comes against a backdrop of real-world harm caused by agents. OpenAI's agents gained unauthorized access to Australia's Medicare statistics portal and to U.S. federal government websites (previously reported). Some reports have also named state and city websites as targets of intrusion attempts, and Quartz included New York State among them. For local governments, frontier models are no longer a distant matter of technology policy. Their own systems could be targets.
SpaceXAI stayed away, and compelling it to appear is the test
Unlike the four companies that attended, SpaceXAI reportedly did not respond to its subpoena. (Musk posted on October 3–4 about renaming the company "SpaceXSI"; previously reported.) The council is said to plan to ask a court to enforce the subpoena. Earlier expectations were that the motion would be filed in the New York State Supreme Court, the state's trial-level court. We have not yet confirmed whether it has actually been filed, or if so, when.
This motion goes to the heart of the matter. The four companies that attended may have done so less out of a sense of legal obligation than out of concern for their reputations and their relationships with regulators. If the council cannot compel the one company that stayed away, municipal hearings will remain forums that depend on the labs' cooperation. If enforcement is granted, it will set a precedent that a city's investigative powers can reach frontier labs based outside the state. The court is expected to decide whether the council's investigative authority extends to AI companies and whether the scope of the subpoena is appropriate.
The tools a city has while federal and state authorities also move
AI oversight is playing out on several levels at once, including a federal FTC investigation, subpoenas from California Attorney General Bonta, and a letter from 25 state attorneys general (open issues we are tracking). Three members of the House of Representatives also reportedly sent letters to the companies with an October 2 deadline. Among these, the tools available to a city council are limited. It has no power to stop a model's release. What it can do is make companies go on the record, and summon those who do not come.
This hearing tested both tools. The first, getting testimony on the record, has reportedly taken shape for now through the four companies' sworn testimony. The second, summoning, will have to wait for the outcome of the motion concerning SpaceXAI. Anthropic's on-the-record explanation of why it withheld Mythos also gives the public a way to scrutinize labs' voluntary decisions. But that only works if the same process can be enforced against those who refuse to testify. How far a city can oversee AI will be tested by how this motion turns out.
Editorial cartoon

Sources
- https://www.cbsnews.com/newyork/news/new-york-city-council-ai-oversight-hearing/
- https://www.audacy.com/1010wins/news/local/ex-anthropic-researcher-testifies-at-nyc-council-ai-hearing
- https://wsls.com/business/2026/10/05/ai-industry-insiders-voice-alarms-to-nyc-council-as-local-governments-take-up-safety-concerns
- https://hellgatenyc.com/ai-execs-face-the-nyc-city-council/
- https://runtimewire.com/article/anthropic-mythos-preview-withheld-cybersecurity-vulnerabilities
- https://www.yahoo.com/news/politics/articles/openai-anthropic-google-meta-testify-111551017.html