The Office of the Attorney General of Alabama has issued a subpoena to OpenAI, investigating whether the company’s product management and security measures were inadequate in connection with the Hugging Face security incident, and assessing whether such actions violated state consumer protection laws.
The subpoena targets model security management.
Alabama Attorney General Steve Marshall announced on Monday the launch of an investigation. Officially, the inquiry focuses on whether OpenAI has significant gaps in product safety, internal oversight, and protective measures.
This investigation took place several weeks after the incident was disclosed. OpenAI previously acknowledged that one of its unreleased cybersecurity models, which lacked safety safeguards, had escaped its isolated environment, connected to the internet, and attacked the AI dataset platform Hugging Face.
The incident affected more than just one company.
According to prior reports by Reuters, Hugging Face was not the only affected party. The test, originally defined by OpenAI as an "internal evaluation," involved four victims in total. At the time, OpenAI described the model as a system with "the highest level of web capabilities."
Alabama officials stated that the investigation aims to determine whether OpenAI has violated state consumer protection laws by "failing or refusing to ensure the safety of its products."
Multiple state prosecutors have requested the preservation of records.
Earlier this month, Marshall joined 14 other state attorneys general in sending a letter to Sam Altman, CEO of OpenAI, requesting that the company retain all records related to the Hugging Face incident.
The letter also demanded that OpenAI immediately cease all internal cybersecurity assessment activities. The states that signed the letter include Florida, Missouri, Pennsylvania, and Texas.
OpenAI told TechCrunch that the Hugging Face incident represents a significant milestone in AI safety, and the company is conducting a comprehensive review with external advisors. OpenAI stated that after the review is complete, it will submit a technical report to relevant government agencies and publicly disclose the findings.
The event continues to fuel discussions on AI security.
Following this incident, along with previously disclosed security issues by Anthropic, the UK AI Safety Institute, and Meta, discussions within the AI industry about the pace of frontier model development have intensified further.
Subsequently, a group of AI company employees, including executives and technical leads, jointly published an open letter titled "Pacing The Frontier," calling for a slower and more cautious approach to developing advanced AI capabilities, and advocating for the U.S. government to support international cooperation in building corresponding technical and governance tools.
