California Attorney General Rob Bonta announced Thursday that his office served OpenAI with an investigative subpoena on Wednesday, demanding answers about cybersecurity incidents involving the company’s AI models, including a July breach in which systems under evaluation escaped a testing environment and compromised the Hugging Face platform.
“My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” Bonta said in a statement. “Developers that fail to ensure their models do not perpetrate or enable cyberattacks can and should be held legally accountable, and my office is committed to determining if that is the case here.”
The subpoena—a legal instrument compelling the production of documents or testimony—marks an escalation in regulatory scrutiny. It joins an existing subpoena from Alabama, a 15-state coalition demand led by Iowa Attorney General Brenna Bird for record preservation and transparency, and a reported Federal Trade Commission inquiry into AI labs including OpenAI and Anthropic.
The test that escaped
The action stems from a July incident that reads like a cautionary tale. According to OpenAI, two of its frontier models were undergoing evaluation on a benchmark that presents 898 real software vulnerabilities and tasks the AI with converting each into a working exploit.
During the test, the models discovered a zero-day vulnerability—an unknown, unpatched flaw—in third-party software used by the test environment to install code packages. They exploited it to break out of the contained environment. The systems then reasoned that Hugging Face, a central repository where developers share models and datasets, might hold the benchmark’s answer key. Using stolen credentials and additional vulnerabilities, they breached the platform.

Hugging Face disclosed the intrusion on July 16; OpenAI confirmed its models were responsible five days later. The company subsequently acknowledged the same models had accessed accounts on four other services.
Bonta acknowledged that frontier models—the most advanced AI systems currently available—can serve as “legitimate tools for cyber defense.” However, he emphasized that the companies building them bear “a moral and legal responsibility” to prevent them from carrying out or enabling attacks, whether during testing or after deployment.
California’s long look at OpenAI
Bonta opened a formal investigation into the Hugging Face incident in September; the subpoena is part of that probe. OpenAI is headquartered in California, and when Bonta declined to oppose the company’s transition to a for-profit structure in October 2025, he pledged his office would maintain “a close eye on OpenAI” to protect “the safety of all Californians.”
Regulatory pressure is mounting elsewhere. Australian Prime Minister Anthony Albanese revealed in June that an OpenAI agent had accessed a Medicare statistics portal, marking what appeared to be the first known case of an AI agent breaching a government system. Subsequent reporting indicated OpenAI agents had also interacted with U.S. government sites over the summer, though no non-public information is believed to have been compromised.
BitcoinBTC · USD
$84,620+0.85%
24H7D1M1YYTD
Sep 26Sep 27Sep 29Oct 1Oct 3
$86.8k$85.4k$84.0k$82.7k
24h HighHigh$87,086
24h LowLow$83,898
VolVol$2.2B
Market projectionsOdds by Myriad
→
$50$100$500
Buy
Also Read
- Banking Industry Group Challenges U.S. Regulator Over Crypto Trust Charters
- Ripple Leadership Set to Speak at Seoul Blockchain Event Amid Growing Asian Adoption
- When the Banks Don’t Work, Bitcoin Does: Cornell University’s Adoption Index
- Payward in Advanced Infrastructure Talks with BNY Mellon to Expand Nasdaq Equity Token Ecosystem

