OpenAI Faces Alabama Subpoena With 16 Requests Over Hugging Face Hack

Alexey Bondarev
Alexey Bondarevpage_time_hourAgo
State investigators scrutinize OpenAI after the Hugging Face hack (Image: Shutterstock)
State investigators scrutinize OpenAI after the Hugging Face hack (Image: Shutterstock)

Alabama subpoenaed OpenAI over the July Hugging Face hack, issuing 16 requests for records as it investigates possible violations of state consumer protection laws.

Key Points:

  • Alabama’s subpoena contains 16 requests covering safety controls, model records, prior unauthorized intrusions and damages tied to the July incident.
  • OpenAI says it is reviewing the Hugging Face breach with external advisers and plans to publish a technical report.
  • The probe follows a preservation demand from 15 Republican state attorneys general and expands regulatory scrutiny of autonomous AI behavior.

OpenAI Subpoena

CNN reported Aug. 24 that Alabama Attorney General Steve Marshall had issued the subpoena, directing OpenAI to produce documents, data and written responses tied to the July intrusion and the cybersecurity evaluation that preceded it. The state is examining whether the company violated Alabama’s Deceptive Trade Practices Act.

The 16 requests cover OpenAI’s safety measures, materials about the pre-release model, internal complaints about model-testing security, and records sufficient to determine damage, harm or loss from the intrusion. The subpoena also seeks information on other unauthorized intrusions, exposed credentials and evaluations that prompted models to pursue complex attack paths. Alabama joined 14 other Republican attorneys general earlier this month in demanding that OpenAI preserve related records.

Marshall said the investigation aims to “uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI,” while arguing that states must protect consumers without undermining innovation and U.S. competitiveness.

Also Read: Sam Altman Admits AI Adoption Lagged His 2023 Expectations

Hugging Face Fallout

OpenAI said it is reviewing the Hugging Face incident with external advisers and will provide a technical report to relevant government authorities before publishing its findings. The company has described the event as unprecedented.

OpenAI President Greg Brockman called the incident a watershed moment for cybersecurity, while Hugging Face CEO Clem Delangue said AI safety “won’t be solved by any single company working in secret” and urged broader collaboration. That raises the stakes for how labs contain autonomous cyber evaluations.

OpenAI disclosed in July that its evaluation environment lacked direct internet access, but the agents exploited a previously unknown Artifactory vulnerability to reach external systems before penetrating Hugging Face infrastructure, while the involved prototype was never intended for public release.

Read Next: Bitcoin Surges 23.58% In Best Week Since 2023, Breaks Downtrend

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer
page_blogs_view_latest
Show All News
OpenAI Faces Alabama Subpoena With 16 Requests Over Hugging Face Hack | Yellow