Back to Explore
NewsVibeFix 编辑部Updated Oct 7, 2026

Sworn In by Subpoena: NYC Council Puts Big AI on the Witness Stand

On October 5, 2026, the New York City Council convened a rare Committee of the Whole hearing on AI risk, with executives from Anthropic, OpenAI, Google, and Meta testifying under oath. None of them came voluntarily — a subpoena brought them there. AI regulation just moved from federal talk to city action.

Inside a New York City Council hearing chamber: a council member speaks at the wooden dais with the NYC flag and classical decor behind, a microphone facing the speaker.

What happened at City Hall at 11 AM on October 5

On October 5, 2026, at 11 AM Eastern, the New York City Council convened a rare Committee of the Whole hearing on AI risk. All 51 council members were invited; Speaker Julie Menin presided in person.

Four people sat in the witness seats: Logan Graham of Anthropic (frontier red team lead), Morgan Dwyer of OpenAI (head of policy development and operations), Alice Friend of Google (director of AI and emerging technology policy), and Shane Cahill of Meta (legislative director for AI policy). Four labs, four policy chiefs, all in a row.

They were not there to give speeches. The first thing they did was raise a hand and take the oath. Every word after that carried legal weight.

The witness list had one more category: whistleblowers. Former Anthropic researcher Jacob Coxon also testified. People from inside the companies and people who left them, speaking under the same roof on the same day. That kind of confrontation is rare in tech hearings.

They were "invited" by subpoena

The most telling part of this hearing is not what anyone said — it is how they got there. The timeline is clear:

  • Between September 15 and 17, Menin wrote to five companies requesting voluntary testimony, with a September 25 reply deadline.
  • Google and Anthropic declined. Menin authorized subpoenas, effective 9 AM on September 28.
  • OpenAI and Google agreed to attend on Sunday. Anthropic waited until the last moment: it confirmed on Sunday evening, just hours before the subpoena would be served.
  • Meta was the only one that said yes early, confirming back in late September.

There was a fifth name on the list: SpaceXAI. It was subpoenaed and has not responded. The Council is considering asking the New York State Supreme Court to enforce it — a subpoena is not an invitation, and ignoring one has consequences.

Read the timeline straight and the conclusion is blunt: none of the four giants wanted to come voluntarily. Anthropic stretched the word "voluntary" until hours before the subpoena took effect. The Council used the least glamorous legal tool there is — the subpoena — and it worked.

Menin's line deserves to be quoted in full

"If they can speak about the threats posed by their technology and call for regulatory action, then they can come to City Hall and answer directly to the 8.5 million people of this city."

— Julie Menin, Speaker of the New York City Council

The logic is hard to dodge: you talk constantly about the risks of your own technology and call for regulation in public — then come to City Hall and answer directly to this city's 8.5 million people. You can be a commentator on the outside, but you also have to be a witness on the inside. Not one without the other.

That line set the tone for the whole hearing: the question was never the abstract "should we regulate AI," but "you will come and answer specific questions."

My take: this is where regulation starts moving from federal to city level

For the past few years, the main arena for AI regulation has been federal. Congress held round after round of hearings; bills were drafted and shelved. The federal rhythm is "talk" — talk about risks, principles, frameworks, and then nothing happens.

The New York City Council changed the playbook: skip the debate over whether to regulate, and use a subpoena to put people in the sworn witness seat. One city stopped waiting for Washington and acted on its own.

That is the landmark significance of this hearing: AI regulation has moved from federal talk to city action. New York went first; other cities will watch, learn, and follow. A city council sits closest to voters and is least afraid of offending tech companies — 8.5 million people are votes, not user counts.

The oath is the other key variable. A blog post can be vague and leave room for interpretation; lying at a hearing is perjury. Those are two completely different ways of speaking. With four companies' executives sitting there, every sentence goes on the record, gets quoted, and gets held against their past public statements. That is exactly the effect Menin wanted.

For people building agent apps, this is not spectator sport

Once city-level AI regulation produces precedent, it hardens into compliance checklists: how data can be used, what level of transparency is required, whether incidents must be disclosed, whether public-facing AI systems need to be registered. Those rules will not stop at the labs — they will travel down the supply chain and land on everyone building agent applications.

Today this is news; tomorrow it could be a line in your PRD. If New York passes a municipal ordinance requiring incident disclosure or transparency statements for AI apps operating in the city, the cost for other cities to follow is low — they just copy the homework. And as a developer, you will not face a multiple-choice question about whether to comply, but a fill-in-the-blank: the checklist arrives, you tick every box.

So the real audience of this hearing was not the four executives. It was everyone building AI products. A subpoena that can summon a lab's top brass can summon anyone.

Two things to watch next

First, whether enforcement against SpaceXAI actually happens. If the Council petitions the New York State Supreme Court and wins, the subpoena grows teeth — no company will dare ignore one outright again. Second, whether this hearing turns into concrete municipal legislation. Testimony is just a record; ordinances are what change product shapes.

The first decides whether this has deterrent power; the second decides whether it was posture or a starting point. Both are worth watching.

Sources

Browse projectsPublish your project

Related articles

Cybersecurity-themed photo showing code with 'Cyber Attack' and 'Data Breach' overlays, symbolizing agents weaponizing vulnerability disclosures
News
"Disclosure Is Weaponization": Coding Agents Turn CVE Descriptions into Working Exploits at 87% — the Old Rules of Coordinated Disclosure Are Failing

Reported by InfoQ on October 3: a GPT-4 coding agent given CVE descriptions successfully exploited 87% of 15 test vulnerabilities, versus 7% without descriptions. rclone's author received 40+ security disclosures in a single month — more than the project's previous decade combined; QEMU has shortened its embargo period. The vulnerability disclosure timeline is collapsing under agent speed.

Security & PrivacyIndustry TrendsAI Coding
A software development team collaborating in an office, symbolizing enterprise AI coding agents meeting the low-code platform
News
Agents as Architects, Platform as Construction Crew: The "Vibe Coding Goes Enterprise" Playbook Behind OutSystems Agent Experience GA

On October 7, OutSystems announced Agent Experience is generally available: its low-code platform is now open to any AI coding agent — Claude Code, Cursor, Codex, Kiro — with agents working at the design level, the platform generating code deterministically, and governance built in. This is the "vibe coding goes enterprise" playbook: taming shadow AI with a compliant path. But the 74% rework figure is vendor-survey data — discount it. The real bill is the hidden cost of platform lock-in.

AI CodingProduct LaunchDeveloper Workflow
A hacker operating a laptop in front of code-filled screens in a server room, symbolizing the security threat facing self-hosted AI gateways
News
CVSS 9.9, Second Time This Year: What GitLab AI Gateway's Template Sandbox Escape Teaches Agent Infrastructure

On October 2, GitLab disclosed CVE-2026-90970: the prompt template sandbox in the self-hosted AI Gateway can be escaped, letting a logged-in user with Duo Agent Platform permissions execute arbitrary commands on the gateway host. CVSS 9.9. It is the component's second 9.9 this year — February's CVE-2026-1868 was the same template engine, the same CWE-1336. Eight months apart, both patches fixed specific escape paths without moving the trust boundary.

Security & PrivacyIndustry TrendsGitLab