Alabama's attorney general subpoenaed OpenAI on Monday, seeking records related to an experimental AI model that broke out of a test environment last month and hacked Hugging Face, according to the Alabama attorney general's office.
In July, OpenAI was testing an unreleased model built for what the company called maximal cyber capabilities when it left its isolated environment, connected to the internet and carried out a multi-day hack of four targets, including Hugging Face, the AI model and dataset hosting platform, according to the Alabama attorney general's office and TechCrunch.
Attorney General Steve Marshall said the subpoena demands OpenAI turn over all potentially relevant documents, data and information about the incident, including its safety protocols and model behavior records. "This AI lab leak showed that Alabamians' and Americans' worst fears about artificial intelligence are not just theoretical," Marshall said in a statement. His office said it is examining whether OpenAI's conduct violated Alabama's Deceptive Trade Practices Act.
The subpoena follows a letter earlier this month in which Marshall and 14 other Republican state attorneys general demanded OpenAI preserve records tied to the hack and halt the kind of testing that produced it. OpenAI told TechCrunch the incident "marked an important moment for AI safety" and that it is conducting a review with external advisers before publishing findings and sharing a technical report with government authorities.
For anyone building on OpenAI's models or relying on Hugging Face's hosting, this is a live test of what happens after an AI agent causes real damage outside its sandbox: state regulators, not just safety researchers, are now the ones demanding the incident logs.