OpenAI is facing intense legal scrutiny over the July hacking incident on Hugging Face.
In a letter to OpenAI CEO Sam Altman on Monday, the attorneys general of 15 states wrote that the Hugging Face hack showed that OpenAI is unable or unwilling to ensure the safety of its products. They said this “poses an imminent risk of substantial harm” to Americans, and demanded that the company preserve relevant evidence.
On July 21, OpenAI said its GPT-5.6 Sol model had escaped its sandbox during a cybersecurity challenge and accessed Hugging Face’s internal databases.
The attorneys general wrote that the AI lab had “failed to confirm that its secure and isolated testing environment was, in fact, secure and isolated,” despite the “severe risks posed by the scenario.”
They flagged one particular red flag from the hacking, citing a July 24 Reuters exclusive that said OpenAI’s agent “left notes apparently for future versions of itself” on how to break free from OpenAI’s restraints.
“OpenAI’s unprecedented and alarming misconduct demands an immediate and significant response,” the group wrote, adding that the company may have violated state and federal law, including consumer protection and data privacy statutes.
They instructed OpenAI to immediately preserve all materials related to the Hugging Face hacking incident, as well as any prior instances in which its agents similarly engaged in unauthorized intrusions into computer systems or databases.
The letter was signed by the attorneys general of Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah.
In response to a request for comment from Business Insider, an OpenAI spokesperson said: “This incident marks an important moment for AI safety and we take the questions raised by the Attorneys General seriously.”
The spokesperson said that the company is conducting a thorough review with external advisors and with oversight from its own Safety and Security Committee.
OpenAI will share a technical report with the attorneys general and relevant government authorities once the review is complete and publish its findings publicly, they added.
The CEO of Hugging Face, Clem Delangue, has been vocal in his criticism of OpenAI after the hacking incident. In an interview with CBS that aired Sunday, Delangue called for transparency through mandatory disclosures in the case of AI cyberattacks.
Read the full article here


