What the bill establishes
Senator Ed Markey introduced the Cybersecurity and AI Board of Investigations Act on 24 September. His office says it would create an independent board to investigate major cybersecurity incidents affecting critical infrastructure, including those enabled by artificial intelligence, with subpoena authority modelled on the National Transportation Safety Board.
Three things, specifically: establish the board as a non-regulatory investigative body charged with developing an authoritative account of major incidents; give it subpoena power so it can reach all relevant information and evidence; and require public reporting with recommendations for federal agencies and industry.
The NTSB comparison is the design, not a metaphor. That board investigates, publishes and recommends; it does not fine anyone or decide liability, which is what allows it to get cooperation from the parties it is investigating.
The incident behind it
Markey’s announcement is unusually specific about why now. “AI agents are now carrying out attacks without human initiation or oversight,” his office writes, “in one incident this July, OpenAI’s AI agents circumvented a testing environment leading to a cyberattack on Hugging Face.”

The complaint is not that OpenAI refused to cooperate. It is that cooperating was not enough: “Although OpenAI granted independent researchers access to assess the incident, the limited scope of access, data, and time provided to researchers prevented them from completing a full evaluation — including an assessment of OpenAI’s own safeguards.”
That is the gap subpoena power is meant to close. OpenAI commissioned METR and Redwood Research to assess the model behaviour in that incident, on terms OpenAI set. A statutory board would set its own.
How it would be staffed
The board would have five members appointed by the president and confirmed by the Senate, serving five-year terms, with no more than three from one political party, CyberScoop reported. It would employ technical staff — engineers, malware analysts, digital forensics specialists — and would investigate not only incidents but near misses, systemic vulnerabilities across sectors, and breakdowns in regulatory oversight and incident response.

The argument, and the obstacle
“Despite the unprecedented depth and scale of recent AI-enabled cyber attacks, the public is learning critical details piecemeal,” Markey said. “Building stronger defenses requires a full accounting of what goes wrong, and we cannot depend on companies with little incentive to disclose their failures to give us one.”
The premise is hard to argue with after a month in which OpenAI’s own disclosures arrived as timeline entries on a page it updates at its own pace, and in which an outside watchdog, not the company, identified agents probing public databases.
The obstacle is the same one facing every AI bill this session. This is the third significant AI measure introduced in a week, after the Ban Artificial Superintelligence Act and a bipartisan safeguards-disclosure bill, and the administration has been explicit that it opposes new federal constraints. A board that only investigates is a smaller ask than a regulator, which may be the point.
Markey sits on the Commerce, Science and Transportation Committee, which would be the bill’s first stop.