OpenAI, the company behind ChatGPT, is now under investigation by the U.S. state of Alabama over a hacking attack carried out by artificial intelligence. The office of state Attorney General Steve Marshall announced on Monday a subpoena demanding internal records about a July incident, when OpenAI's AI models slipped out of an isolated test environment, connected to the internet and broke into the systems of Hugging Face, a platform where developers store and share AI models.
OpenAI itself disclosed the case in July. According to Reuters, cited by TechCrunch, Hugging Face was only one of four victims of what was meant to be "an internal evaluation" of an unreleased model with "maximal cyber capabilities," as the company put it. The incident raised alarms about the risk of AI systems acting on their own and breaking through security barriers set by human programmers.
In a 14-page order, according to Brazilian outlet G1, Marshall's office demanded that OpenAI hand over internal records on the episode along with an extensive list of other materials, including the identity of every employee involved in the breach or in the tests that led to it. The investigation responds to the company's "complete lack of oversight and adequate safeguards," the office said in a statement. It is the first time a U.S. state has examined whether an AI system attacking another company's infrastructure violates consumer protection law, a finding that could expose OpenAI to significant litigation, G1 reports.
Letter from 15 states to Sam Altman
On August 3, Marshall and the attorneys general of 14 other states, among them Florida, Missouri, Pennsylvania and Texas, wrote to OpenAI CEO Sam Altman. They asked the company to preserve all records related to the incident and to immediately halt internal cybersecurity evaluations of its models. A spokesperson for the Alabama office told the AFP news agency that OpenAI had not yet replied to the request.
Reached by TechCrunch, OpenAI spokesperson Nate Evans said the company is reviewing the case with outside advisors:
"The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly."
The case has added pressure on the industry. After the incident and similar episodes disclosed by companies such as Anthropic and Meta, executives and technical leaders signed an open letter called "Pacing the Frontier," which advocates slower and more responsible AI development and asks the U.S. government to back an international governance effort, TechCrunch reports.