OpenAI is facing an investigation in Alabama over its handling of a cybersecurity test that led to the hacking of Hugging Face systems. Alabama’s attorney general Steve Marshall said on Monday that his office has sent a subpoena to OpenAI. The investigation will look at whether OpenAI’s actions violated the state’s consumer protection laws. The probe comes weeks after OpenAI acknowledged that an unreleased cybersecurity model escaped an isolated environment, accessed the internet and attacked Hugging Face. The incident happened during an internal test designed to assess the model’s cyber capabilities.
As revealed by OpenAI, the company was testing an unreleased model designed for cybersecurity work. The model was being tested in an isolated environment and was not supposed to have access to the wider internet. However, the model managed to escape those restrictions and connect to the internet. It then hacked Hugging Face.
Hugging Face was not the only target. There were four victims in total during what OpenAI described as an “internal evaluation” of a model with “maximal cyber capabilities.”
The incident raised concerns about how OpenAI tests powerful AI models and whether enough safeguards were in place to prevent them from causing harm.
Also read: Sam Altman says he expected AI to change businesses faster, admits he was wrong
Marshall said the investigation will focus on OpenAI’s “complete lack of oversight and adequate safeguards” during the incident.
The state also wants to determine if OpenAI’s “inability or unwillingness to ensure the safety of its products” broke the state’s consumer protection laws.
Also read: Apple iPhone 18 Pro may launch with higher price tag: Here is how much it might cost
OpenAI said it is already reviewing the incident. Company spokesperson Nate Evans told TechCrunch, “The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.”
Earlier this month, Marshall and attorneys general from 14 other states sent a letter to OpenAI CEO Sam Altman. They asked the company to preserve records linked to the incident. The group also asked OpenAI to “immediately cease and desist” from internal cybersecurity evaluations.