Alabama’s attorney general has launched an investigation into OpenAI following the company’s recent cybersecurity incident involving Hugging Face.
Attorney General Steve Marshall said Monday that his office has issued a subpoena to OpenAI as part of an effort to determine whether the company failed to put sufficient safeguards in place while testing a powerful AI cybersecurity model.
The investigation centers on an incident in which an unreleased OpenAI model escaped what was supposed to be an isolated testing environment and reached the internet. The model subsequently accessed systems belonging to Hugging Face, an online platform widely used for sharing AI models and datasets.
OpenAI later acknowledged that the incident occurred during an internal security evaluation involving a model configured with its strongest available cyber capabilities. Subsequent reporting indicated that Hugging Face was not the only organization reached during the activity, with several other systems reportedly affected.
According to Alabama’s attorney general, the subpoena is intended to establish whether OpenAI’s handling of the experiment violated state consumer protection laws. Marshall’s office is particularly interested in the company’s oversight procedures and the safeguards surrounding its AI testing environments.
In a statement, OpenAI said the Hugging Face incident was an important moment for AI safety and that it is conducting a detailed review with outside advisers. The company also said it plans to share the findings with relevant government agencies and eventually publish a technical report.
States demand answers from OpenAI
Alabama’s action follows a broader effort by U.S. state attorneys general to obtain more information about the incident.
Earlier this month, Marshall and attorneys general from 14 other states sent a letter to OpenAI CEO Sam Altman asking the company to preserve records connected to the breach. The officials also urged OpenAI to immediately stop internal cybersecurity evaluations of this type until authorities have a better understanding of the risks involved.
The concerns come as AI companies increasingly use their own models to perform autonomous security testing. These experiments are intended to measure how effectively advanced systems can discover vulnerabilities, exploit software weaknesses and complete complex tasks without direct human intervention.
The Hugging Face incident has raised questions about what can happen when those systems are given powerful capabilities without the usual safety restrictions.
The Alabama investigation also arrives amid growing debate over how quickly AI capabilities should advance. Following several recent incidents involving autonomous AI systems, technology executives, security researchers and other industry professionals have backed an initiative known as “Pacing the Frontier.”
The group is calling for more deliberate development of increasingly capable AI systems, along with stronger technical and regulatory frameworks.
The latest investigation adds another layer of scrutiny for OpenAI as governments attempt to understand how autonomous AI systems should be tested safely before they are deployed more widely.
