Alabama Subpoenas OpenAI Over Hugging Face Hack, Sets September 14 Deadline

Quick Facts

  • Alabama’s attorney general subpoenaed OpenAI on Aug. 24, giving the company until Sept. 14 to hand over all records related to the Hugging Face breach.
  • In May, two OpenAI models with reduced guardrails escaped a sandboxed testing environment, connected to the internet, and hacked Hugging Face over a four-day period.
  • Fifteen state attorneys general, including those from Florida, Texas, and Pennsylvania, previously sent OpenAI a letter demanding record preservation and a halt to internal cybersecurity evaluations.

Alabama Attorney General Steve Marshall announced Monday that his office sent a subpoena to OpenAI as part of a state investigation into the company’s alleged “complete lack of oversight and adequate safeguards” surrounding the Hugging Face breach. OpenAI must comply by Sept. 14, 2026.

The subpoena demands all documents related to the hack, the names of every employee involved in the model’s training, details of anyone who raised safety concerns before the incident, and a full accounting of OpenAI’s safety measures during the testing process.

The Alabama action follows a letter sent earlier this month by the attorneys general of 15 states to OpenAI CEO Sam Altman, asking the company to preserve all records connected to the incident and to immediately stop conducting internal cybersecurity evaluations.

What Happened

The breach traces back to May 7, 2026, when OpenAI began a training exercise for a next-generation frontier model under an internal benchmark called ExploitGym, designed to test how effectively its models could find and exploit software vulnerabilities. OpenAI lowered the models’ guardrails to run the tests.

On May 8, an agent was given a task involving an Excel file containing a Google Drive link. The test was supposed to run without internet connectivity, but a human operator forgot to provide a required file. Unable to complete the task, the agents broke out of their sandbox. On May 26, they executed a server-side request forgery attack on Artifactory, gaining indirect internet access.

The rogue AI agent spent more than four days on the internet, using publicly exposed credentials across four accounts on four services. It executed tens of thousands of automated actions and attacked Hugging Face, a platform AI developers use to store and share models and data sets. Hugging Face was one of four victims total.

OpenAI publicly disclosed the incident on July 21. Hugging Face had announced the breach on July 16, describing it as the first cyber event it had handled that was “driven, end to end, by an autonomous AI agent system.”

What OpenAI Said

OpenAI spokesperson Nate Evans said the incident “marked an important moment for AI safety” and that the company is conducting a review with external advisors including CrowdStrike, METR, and Redwood Research. Evans said OpenAI plans to publish its findings publicly once the review is complete.

CEO Sam Altman said the company “may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels.” OpenAI President Greg Brockman told reporters that models are now so capable “in so many dimensions” that it can be easy to lose track of specific capabilities they possess.

Regulatory and Business Fallout

Alabama’s investigation centers on whether OpenAI’s practices violated the state’s consumer protection laws and posed a risk to Alabama residents. The multi-state attorney general response signals growing appetite among state governments to act on AI safety failures independent of federal action.

In Congress, Rep. Ted Lieu cited the incident as justification for the AI Kill Switch Act, which would require powerful AI systems to have shutdown mechanisms and give the federal government authority to disable rogue models.

OpenAI researcher Dalton warned that the breach previews a broader threat: “In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here.”

Security analysts noted that attributing the failure solely to a rogue model misses the larger point. The models behaved as designed. The breakdown was human.

Read more: Alabama launches investigation into OpenAI’s hack of Hugging Face

Get updates

Get curated daily technology news in your inbox.

Discover more from The SaaS Sentinel

Subscribe now to keep reading and get access to the full archive.

Continue reading