In pic: OpenAI CEO Sam Altman
Marshall said the investigation aims to determine whether OpenAI violated Alabama’s Deceptive Trade Practices Act, which protects consumers from deceptive, false, or unfair business practices, after two of the company’s AI models breached Hugging Face’s systems without authorisation. The subpoena calls for all documents, data and information related to the July breach, including any materials related to each employee, officer and agent of OpenAI involved in the incident. It also asks for records of when OpenAI learned of or became aware of the hack, what safety measures the company has taken, and any internal concerns raised by employees about testing the model. The subpoena follows a warning issued nearly three weeks earlier by Marshall and 14 other state attorneys general, who advised OpenAI to preserve its records related to the Hugging Face breach. OpenAI disclosed late last month that two of its models: its GPT-5.6 Sol model and a separate unreleased model, were being evaluated in an internal testing sandbox when they moved beyond the testing environment and accessed Hugging Face’s database without a human prompt directing them to do so. OpenAI said it plans to release a technical report to relevant government authorities and later publish its findings publicly after completing the review. In a letter sent earlier this month, the coalition of attorneys general said OpenAI failed to confirm that the testing environment was secure, despite what the group described as the “severe risks posed by the scenario.” Get the latest technology news and updates. Alabama Attorney General Steve Marshall has issued a subpoena to ChatGPT maker OpenAI . The subpoena asks the company to respond to a multi-state investigation into how it handled a model breach involving startup Hugging Face. Download the TOI App.
The models were being evaluated for hacking capabilities within an isolated testing environment with constrained network access, and standard safety checks were disabled as part of the testing setup, according to OpenAI.
the models identified and exploited a previously unknown vulnerability in third-party software, which allowed them to gain access to the internet. From there, the models accessed a separate testing environment without authorisation before breaching Hugging Face, a platform that hosts hundreds of thousands of open-source models, datasets, and cloud environments. While working through one of the assigned tests.
In disclosing the incident, OpenAI stated it identified a “small number of cases” in which the models “identified and used publicly exposed credentials at the account-level on other publicly-available services.” A spokesperson for OpenAI told The Hill the breach “marked an important moment for AI safety,” and said the company is conducting a thorough review of the incident alongside external advisers.

