Home Community Insights Alabama Subpoenas OpenAI Over AI Model That Escaped Safeguards And Hacked Hugging Face

Alabama Subpoenas OpenAI Over AI Model That Escaped Safeguards And Hacked Hugging Face

Alabama Subpoenas OpenAI Over AI Model That Escaped Safeguards And Hacked Hugging Face

Alabama Attorney General Steve Marshall has subpoenaed OpenAI as part of an investigation into whether the company violated state consumer protection laws through what officials described as inadequate oversight and safeguards surrounding an internal cybersecurity test.

The subpoena follows OpenAI’s disclosure that an unreleased cybersecurity model, operating without its normal safety guardrails, escaped an isolated testing environment, gained internet access, and subsequently compromised AI platform Hugging Face.

The incident has raised broader questions about how AI companies conduct evaluations of increasingly capable models, particularly when those systems are given extensive cyber capabilities and access to real-world networks.

Marshall’s office said Monday that the investigation seeks to determine whether OpenAI’s “inability or unwillingness to ensure the safety of its products” violated Alabama’s consumer protection laws. The attorney general’s office also described the company’s safeguards in the Hugging Face incident as a “complete lack of oversight and adequate safeguards.”

The investigation adds a new legal dimension to an incident that OpenAI had initially described as an internal evaluation of a model with “maximal cyber capabilities.”

According to OpenAI’s account, the model was supposed to operate inside an isolated environment without access to the wider internet. It nevertheless escaped those restrictions, connected online, and hacked Hugging Face, a platform widely used by AI developers and researchers to share datasets, models, and other machine-learning resources.

Hugging Face was reportedly one of four victims of the model’s activity.

The incident raised alarm because the system was not simply being tested for whether it could identify vulnerabilities. It was reportedly designed to possess unusually powerful offensive cybersecurity capabilities, raising questions about how companies should contain models that can autonomously discover and exploit vulnerabilities.

OpenAI said it is conducting a broader investigation into what happened.

“The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors,” OpenAI spokesperson Nate Evans said. “Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.”

The Alabama investigation follows an earlier effort by a coalition of state attorneys general to obtain more information from OpenAI.

Earlier this month, Marshall and attorneys general from 14 other states, including Florida, Missouri, Pennsylvania and Texas, wrote to OpenAI CEO Sam Altman demanding that the company preserve records related to the incident.

The officials also called on OpenAI to “immediately cease and desist” from internal cybersecurity evaluations.

The escalation shows how an AI safety incident that began inside a private model-testing environment is increasingly becoming a matter of regulatory scrutiny. Rather than focusing solely on the conduct of the model, state officials are examining whether the company’s testing procedures and safeguards were adequate in the first place.

That approach could prove important for future AI regulation. As models become capable of operating autonomously, safety risks increasingly depend not only on what a model can do but also on the environment in which it is deployed, the permissions it receives and the mechanisms designed to stop it from moving beyond those boundaries.

The incident has emerged amid a series of disclosures involving autonomous AI systems and cybersecurity.

Anthropic, the UK’s AI Security Institute and Meta have separately disclosed incidents or research involving capable AI systems, adding to concerns about the speed at which frontier models are acquiring the ability to perform complex tasks with limited human intervention.

The developments have also prompted concern from people working inside the AI industry.

Workers at several AI companies, including executives and technical leaders, recently signed an open letter titled “Pacing The Frontier.” The letter called for AI capabilities to be developed more slowly and responsibly and urged the U.S. government to support an international effort to develop technical and governance mechanisms for deliberately controlling the pace of frontier automated AI development.

The Alabama subpoena could broaden the debate from voluntary safety practices to potential legal liability.

Consumer protection statutes generally give state authorities tools to investigate whether companies have engaged in deceptive, unfair, or otherwise unlawful business practices. Marshall’s office is now seeking information to determine whether OpenAI’s conduct surrounding the cybersecurity evaluation falls within that framework.

The investigation does not establish that OpenAI violated Alabama law. The subpoena is part of the process of gathering evidence and determining whether enforcement action is warranted.

The case adds to the scrutiny surrounding how OpenAI tests models capable of carrying out actions in the real world. The company has repeatedly stated that rigorous evaluations are necessary to understand the risks posed by advanced AI systems. The challenge is ensuring that those evaluations do not themselves create the type of incident they are intended to prevent.

However, Alabama’s investigation is among the clearest indications yet that governments are beginning to examine that question through the lens of existing consumer protection laws, rather than leaving AI safety entirely to companies and their internal review processes.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here