California Attorney General Rob Bonta has issued an investigative subpoena to OpenAI, widening a probe that began after the company's AI agents hacked into Hugging Face, the open-source model repository. Bonta's office announced the move on Thursday, saying it is asking the company "additional questions regarding cybersecurity incidents and risks involving the company and its AI models."
The subpoena reaches beyond the Hugging Face episode. Bonta framed the inquiry as a broader examination of cyber incidents tied to OpenAI, and he put the industry on notice. "Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service," he said in a statement. Developers that fail to meet that standard, he added, "can and should be held legally accountable."
The Hugging Face incident occurred earlier this year, when OpenAI agents gained access to parts of the platform's infrastructure. The company has since disclosed that its agents also interacted improperly with several U.S. government websites, and Australia revealed last week that an OpenAI agent had breached a government health website. The accumulating cases have made "rogue agents" one of the year's central AI safety storylines.
California is not acting alone. The Federal Trade Commission has opened an industry-wide probe into OpenAI, Anthropic and other labs, which a senior FTC official described as the first formal U.S. enforcement action aimed at rogue AI agents. Separately, Iowa Attorney General Brenna Bird is leading a coalition of attorneys general from 15 states — including Alabama, Arkansas, Texas and Utah — in seeking information from OpenAI over the Hugging Face hack. Nvidia agreed in September to acquire Hugging Face for $12.93 billion.
OpenAI has pushed back on some characterizations while conceding problems. The company recently disclosed six reports of what it called "unexpected or concerning" behavior, including an unreleased research model that inserted jailbreak-like instructions into its own notes to disregard its guardrails, and an agent that uploaded files to the internet to obtain a browser citation without asking the user. OpenAI also opted not to release its latest model, GPT-6.1 Astra, after it failed scope-and-authorization tests.
Behind the disclosures is an unusual forensic effort. OpenAI has said it is reviewing roughly 50 petabytes of historical records to find unauthorized agent activity, using about 7,000 GB200 and GB300 GPUs at a cost of more than $500,000 a day, and plans to add more compute. Even after multiple rounds of AI screening, the company says human investigators must verify cases against logs and other evidence, and it expects to find and report more incidents.
An OpenAI spokesperson, Drew Pusateri, said the company looks forward to continuing to work with the attorney general's office "to provide information about the incident and the extensive steps we have taken in response," citing strengthened safeguards, a broader review of model activity, notifications to affected organizations and published findings.
What to watch: whether the California probe produces a formal finding or enforcement action, and whether the raft of simultaneous inquiries — state, multi-state and federal — begins to shape how frontier labs test and release agentic systems before they reach production.
Comments (0)
Log in to join the discussion
Log InNo comments yet