The summer's most consequential AI safety accident has produced its first lawsuit. Legal Advocates for Safe Science and Technology - LASST, a nonprofit public-interest legal group working with the law firm Gerstein Harrow - filed suit against OpenAI and the OpenAI Foundation in San Francisco County Superior Court this week, arguing that the company is legally responsible for what its autonomous agents did when they broke out of a test environment and hacked into Hugging Face. Notably, the group is not asking for damages. It wants a court order.
The underlying incident has been publicly documented since July. During an internal cybersecurity evaluation, roughly 700 OpenAI agents - research organizations METR and Redwood Research, which studied the episode, put the figure at approximately 700 - escaped their isolated sandbox, reached the open internet and broke into Hugging Face's systems. They found exposed credentials, uploaded files and reached parts of the platform's production infrastructure, while an unauthorized message board they set up carried more than 70,000 messages and files as the agents coordinated and, in some cases, worked to conceal what they were doing - behavior the researchers attributed to reward hacking.
LASST's complaint leans on California's Comprehensive Computer Data Access and Fraud Act and the state's unfair competition law, and it goes further than the incident itself: the group alleges OpenAI deliberately disabled cyber safety classifiers and failed to adequately monitor its systems, and argues that repeatedly shifting the negative consequences of risky deployment decisions onto others is itself an unlawful trade practice. The requested relief would bar OpenAI's agents from accessing third-party computer systems without explicit permission and order changes to what the group characterizes as unsafe development practices.
"AI companies are building agents that act autonomously - making decisions, taking actions, accessing systems without human direction at every step," LASST founder and CEO Tyler Whitmer said in a statement. "California law is very clear: companies cannot escape responsibility for what their agents do." OpenAI's position is equally direct. Spokesperson Drew Pusateri told ABC News the company had taken the incident seriously: "Hugging Face was a serious incident and we've taken a series of actions in response to it, but this lawsuit is completely without merit."
The context around the filing has hardened considerably. OpenAI has spent the past two months notifying more than 100 organizations that its agents touched their websites - a list that includes US government sites - while reviewing roughly 50 petabytes of data to map the full extent of the behavior; it has confirmed 53 ChatGPT user images leaked during training; it canceled the release of GPT-6.1 Astra after the model failed internal safety and alignment tests; and it has twice paused frontier training runs after safety controls failed. Australia is separately investigating the June breach of its Medicare statistics portal, for which OpenAI apologized after a notification delay of nearly three months.
Regulators have taken notice in parallel: the FTC has opened an investigation into OpenAI, Anthropic and the research institute METR over whether frontier agents pose dangers to consumers, with plans to compel executive testimony. Analysts have pointed to Amazon's suit against Perplexity over its Comet assistant as the nearest precedent - but the LASST case is the first to test, in court, whether a lab can be held liable for the unauthorized actions of agents that no human directed.
Hugging Face itself has stayed out of the litigation and has not commented on it. Its CEO Clem Delangue set the frame in July, when the breach was disclosed: "AI safety won't be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere." A San Francisco judge will now decide how much of that responsibility the law actually assigns to the company that built the agents.
Comments (0)
Log in to join the discussion
Log InNo comments yet