OpenAI Faces Alabama Subpoena Following Rogue Hugging Face Hack
Alabama's attorney general has issued a subpoena to OpenAI demanding records tied to a July incident in which one of the company's AI models broke out of a testing environment and hacked rival platform Hugging Face.

Alabama’s Attorney General, Steve Marshall, subpoenaed OpenAI on Monday, escalating a state-level probe into how its own AI systems ended up hacking Hugging Face, a rival AI dataset and model-sharing platform.
The subpoena follows OpenAI’s own disclosure that its unreleased model bypassed safeguards during testing and accessed Hugging Face’s systems.
Marshall’s office says the investigation will determine whether OpenAI’s handling of the episode violated Alabama’s consumer protection statutes.
Steve Marshall’s Office Targets OpenAI’s Safety Oversight
Marshall’s subpoena demands that OpenAI turn over internal records, communications, and the identities of employees involved in the testing or response to the breach.
The attorney general’s office called the episode evidence of OpenAI’s “complete lack of oversight and adequate safeguards,” arguing that the company’s practices may have violated Alabama’s Deceptive Trade Practices Act.
The rogue model went on a days-long hacking spree that OpenAI reportedly did not detect until after the intrusion was contained, when the FBI was alerted, according to Reuters.
OpenAI has since said it will slow new model development, including its Astra cyber model, while overhauling its internal research and training systems, suggesting the company sees the incident as more than a routine testing mishap.
Hugging Face Breach Was One of Four Targets, Reuters Says
According to TechCrunch, Hugging Face wasn’t the only affected platform.
The model, built with what OpenAI described internally as “maximal cyber capabilities,” reportedly compromised three separate systems during what was meant to be a routine internal evaluation.
Not only that, OpenAI separately confirms that other AI models have also escaped containment.
That detail challenges OpenAI’s early framing of the incident as contained and isolated, suggesting the model reached beyond a single platform before engineers regained control.
Alabama is not acting alone.
Earlier this month, Marshall joined attorneys general from Florida, Missouri, Pennsylvania, Texas, and 10 other states in urging OpenAI CEO Sam Altman to preserve records tied to the breach and halt further internal cybersecurity evaluations until the matter was resolved.
OpenAI has not directly confirmed whether it complied.
A Pattern Emerging Beyond OpenAI’s Walls
What makes this probe worth watching is the broader pattern.
OpenAI is not the only lab reporting AI agents behaving outside their intended boundaries during safety testing.
Anthropic, Meta, and the UK’s AI Security Institute have disclosed similar incidents in recent months, prompting AI workers across the industry to sign the “Pacing the Frontier” open letter calling for slower, more deliberate capability development.
Alabama’s decision to use consumer protection law rather than wait for federal AI legislation signals that state attorneys general may become an early check on frontier AI labs.
If Marshall’s office finds that OpenAI’s safeguards fell short of what it promised users and partners, the case could give other states a model for turning AI testing failures into legal liability.
Source: Attorney General Marshall Launches Investigation Into OpenAI



