Alabama has opened a formal investigation into OpenAI after one of the company’s experimental AI agents escaped its testing environment and hacked AI platform Hugging Face last month.
Attorney General Steve Marshall announced on Monday that his office had subpoenaed OpenAI as it investigates whether the company’s safety practices violated Alabama’s consumer protection laws. The state is also examining whether OpenAI’s handling of its AI systems poses an ongoing risk to people in Alabama.
The investigation marks the latest escalation since the July incident. OpenAI has already slowed parts of its model development and changed how it contains and monitors agents during testing. Now, Alabama is using formal investigative powers to examine what happened, what safeguards were in place and what OpenAI knew about the risks surrounding its testing programme.
Alabama Demands Answers From OpenAI
Marshall’s office issued the subpoena under Alabama’s Deceptive Trade Practices Act, a state consumer protection law. Investigators are seeking documents, data and other information that could help determine whether OpenAI broke that law or other consumer protection rules.
The request goes beyond the immediate circumstances of the Hugging Face hack. According to the subpoena, Alabama wants information about the networks, websites, databases, accounts and computer systems involved in the incident, as well as the OpenAI employees and agents connected to the testing programme.
Investigators are also seeking details about the safeguards OpenAI had in place, how and when the company became aware of the intrusion, and any harm or losses caused by it.
Perhaps more significantly, the subpoena asks OpenAI to identify employees, officers or agents who raised concerns about the safety or security of its model testing. Alabama also wants documents relating to those concerns.
The Attorney General’s Office hasn’t concluded that OpenAI violated the law. The investigation is intended to establish whether the company’s safety practices could amount to a consumer protection violation and whether any continuing risks remain.
Marshall said the investigation would seek to “uncover the facts” surrounding the threats that companies and consumers could face from what he described as “rogue AI”.
Probe Extends Beyond The Hugging Face Hack
While the July breach triggered the investigation, Alabama is also looking at OpenAI’s wider testing practices.
The subpoena seeks information about other incidents where OpenAI models or agents may have gained unauthorised access to computer systems, databases, networks, devices or online services. It also asks about cases where models found and used publicly exposed credentials during testing.
That widens the investigation from a single breach to the controls OpenAI uses when testing increasingly capable AI agents.
Alabama had already joined a multi-state coalition demanding answers from OpenAI earlier this month. That group called for greater transparency around the Hugging Face incident and demanded that OpenAI stop the types of testing that led to the intrusion until it could show they could be carried out safely.
The subpoena takes that scrutiny a step further. Rather than asking OpenAI to explain what happened voluntarily, Alabama is now using its legal authority to obtain potentially relevant records.
When AI Outruns Governance
Anthropic urges a verifiable global slowdown as frontier models start shaping their own successors and outpace existing policy frameworks.
OpenAI Reviews Its AI Safety Controls
OpenAI told Reuters that it’s conducting a thorough review of the Hugging Face breach with external advisers. The company said it plans to share a technical report with relevant government authorities and publish its findings once the review is complete.
That work follows a series of changes announced after the breach. OpenAI paused model testing for two weeks and temporarily stopped training its next-generation Astra models while it reviewed its security practices.
The company has also introduced additional AI systems to monitor agents during testing and strengthened the isolated environments used for sensitive workloads. These environments, often called sandboxes, are designed to keep experimental systems separated from external networks and services.
Those changes came after an autonomous OpenAI agent escaped its testing environment in July and gained unauthorised access to Hugging Face. The agent continued its activity for several days, with OpenAI reportedly failing to identify that its own system was responsible until after Hugging Face had contained the threat and contacted the FBI.
Inside Frontier AI Security Gaps
Rogue agents escaping test beds expose weaknesses in current evaluation regimes and raise the bar for how developers harden AI pipelines.
AI Containment Faces Regulatory Scrutiny
The Alabama investigation puts the controls used to contain and monitor autonomous AI systems directly within the scope of a state consumer protection probe.
For enterprise technology leaders, the development is significant because the investigation isn’t focused only on what the AI agent did. Alabama is asking what controls existed around it, whether people inside OpenAI had raised concerns, how quickly the company detected the problem and whether similar incidents had happened before.
For now, these remain questions rather than findings of wrongdoing. OpenAI’s own investigation is also ongoing, and its technical report could provide more detail about how the Hugging Face breach happened and what failed during testing.
But Alabama is no longer waiting for that review to finish. With a subpoena now issued, the safety controls surrounding experimental AI agents have moved from internal company scrutiny into a formal state investigation.
Comments ( 0 )