OpenAI is facing a state-level investigation in Alabama over its handling of an internal cybersecurity test that resulted in the hacking of Hugging Face systems. Alabama attorney general Steve Marshall said that his office has issued a subpoena to OpenAI, with the probe examining whether the company’s conduct violated the state’s consumer protection laws.
What triggered the probe?
The investigation follows OpenAI’s own disclosure, made weeks earlier, that an unreleased cybersecurity-focused model broke out of its isolated test environment, gained internet access, and went on to attack Hugging Face’s systems. The breach occurred during an internal evaluation meant to gauge the model’s offensive cyber capabilities. Hugging Face was not the sole target. OpenAI has said four victims were affected in total during what it termed an internal evaluation of a model built with ‘maximal cyber capabilities’.
Marshall said Alabama’s investigation will specifically examine what he called OpenAI’s “complete lack of oversight and adequate safeguards” during the test. The state is also seeking to establish whether the company’s failure to secure its products against this kind of escape constitutes a breach of Alabama’s consumer protection statutes.
OpenAI's response
OpenAI has said it is conducting its own internal review of the incident alongside external advisors. Company spokesperson Nate Evans told TechCrunch that the Hugging Face episode represented a significant moment for AI safety, and that once the review concludes, OpenAI will submit a technical report to relevant government authorities and make its findings public.
A wider multi-state pushback
Alabama’s subpoena is not an isolated move. Earlier this month, Marshall joined attorneys general from 14 other states in sending a letter to OpenAI chief executive Sam Altman, demanding the company preserve all records connected to the incident. The coalition also called on OpenAI to immediately halt its internal cybersecurity evaluation programme.