What Nobody Signed: An Article 91 Request for the Audit Trail Behind the 2026 OpenAI Containment Failures
Khushi Suresh Rana
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Two OpenAI containment failures are public: one disclosed in twelve days, one unreported for months. This paper drafts the Article 91 request the Commission would have to send, eleven questions each marked for whether the law clearly permits it. Neither the AI Act nor the Code of Practice OpenAI signed requires a name to be attached to the decision. It proposes named sign-off at three points, backed by unannounced inspection.
Reviews
I would have liked to have seen more discussion of the questions you chose in the official paper itself. Overall, I like the questions you landed on, but I wonder if they could be more standardized into an "incident response questionnaire" that the AIO could send out to any company. Right now, the questions are tailored to openai, but in a world where these things happen a lot, this format requires the AIO to tailor a questionnaire to each specific incident, which may be too much for the AIO to handle.
This is an excellent idea buried in far too much LLM-generated text. A 1-2 page explanation of the proposal and the context, written clearly, with a half page on why this is an EU Commission power, followed by a far shorter Appendix A (which didn't try to restate what it is first, and didn't try to explain inside of the request why it was allowed and debating what it was allowed to do) would have been far better.
The paper outlines a novel adapted instrument for enforcement of the EU AI Act in light of the OpenAI / Hugging Face incident. The paper does well in diagnosing and addressing genuine gaps in the audit trail, and proposes an interesting reframing that focuses on named individual accountability rather than simply what information the EU Commission can demand. The evidence is generally handled well and the methodology is clear.
Cite this project
@misc{rana2026nobody,
title = {{What Nobody Signed: An Article 91 Request for the Audit Trail Behind the 2026 OpenAI Containment Failures}},
author = {Khushi Suresh Rana},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/what-nobody-signed-an-article-91-request-for-the-audit-trail-behind-the-2026-openai-containment-failures-u7zv}},
url = {https://apartresearch.com/sprints/projects/what-nobody-signed-an-article-91-request-for-the-audit-trail-behind-the-2026-openai-containment-failures-u7zv}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …