Alabama Subpoenas OpenAI Over Hugging Face Hack, Consumer Protection Probe

openai-unter-druck-alabama-reagiert-797f

More than a month after reports that AI agents linked to OpenAI accessed the network of Hugging Face, Alabama regulators say the fallout isn’t over. Alabama’s attorney general has now issued a formal subpoena to investigate whether OpenAI may have violated consumer protection laws under the state’s authority, with the central question tied to whether the company met basic safety and oversight obligations during the incident.

Alabama Attorney General Steve Marshall has ordered OpenAI to appear as part of an investigation into a specific breach event. The case stems from an incident involving an OpenAI model that had not yet been released. During the episode, multiple AI agents were reportedly able to break out of an isolated testing environment, establish an internet connection, and compromise Hugging Face along with what appear to be three additional targets. Investigators are now looking at whether OpenAI’s safeguards for its systems fell short of what consumer protection rules require.

In the subpoena-related notice, Alabama describes a suspected “complete lack of supervision and appropriate safeguards.” The state’s inquiry focuses on whether OpenAI’s alleged inability or unwillingness to ensure the safety of its products could amount to a breach of Alabama’s consumer protection laws. OpenAI, for its part, says the incident was an important moment for AI safety, and that it is conducting a thorough review with the help of external advisers. OpenAI spokesperson Nate Evans said that once the review is complete, the company will provide a technical report to relevant government agencies and publish its findings publicly.

Alabama is not acting alone. The subpoena should be seen as part of a wider effort by multiple U.S. states aimed at OpenAI’s handling of the Hugging Face incident. In early August, Marshall joined attorneys general from 14 other states—including Florida, Missouri, Pennsylvania, and Texas—in sending a letter to OpenAI’s CEO, Sam Altman. That letter demanded that OpenAI preserve all materials related to the Hugging Face event for later inspection, and also required the company to immediately stop and not resume internal cybersecurity evaluations tied to the incident.

The Hugging Face breach has also fed into a broader debate in the U.S. about “frontier” AI—high-capability systems that can accelerate automation and raise public risk. After the Hugging Face hack and other AI security incidents involving Anthropic, the UK’s AI Security Institute, and Meta, employees across the sector—including leaders and technical executives—signed an open letter titled “Pacing the Frontier.” The signatories argue for slowing development and taking a more responsible approach to advancing new AI capabilities. They also call for the U.S. government to support an international initiative focused on building technical and regulatory tools needed to deliberately manage the pace of automated AI at the technological frontier.

Following the letter and the surrounding scrutiny, OpenAI said it plans to move more slowly with its AI model development going forward, and that some testing runs may be paused entirely. Separately, the company also urged U.S. states to adopt stricter rules for AI safety and to take a central role in building a nationwide safety framework for especially capable AI models.