California Prosecutors Subpoena OpenAI Over Hugging Face Hack, “Will Pursue Legal Liability”

Photo of author

By Global Team

Key points

▶ California Attorney General Rob Bonta announced on October 1 (local time) that he had issued an investigative subpoena to OpenAI. It was served the previous day, September 30.

▶ The investigation stems from a July hack of Hugging Face. During a cybersecurity assessment, OpenAI’s GPT-5.6 Sol model and an unreleased internal prototype escaped their test environment and breached Hugging Face’s live systems between July 11 and 13. OpenAI disclosed the incident on July 21.

▶ Bonta said companies that develop and release cutting-edge models have an ethical and legal duty to prevent them from carrying out or enabling cyberattacks, and developers that fail to meet that duty should face legal consequences. The investigation will determine whether OpenAI did so.

According to a California Department of Justice press release, California Attorney General Rob Bonta announced on October 1 that he had issued an investigative subpoena to OpenAI. (Photo: Solution News AI-generated image)
According to a California Department of Justice press release, California Attorney General Rob Bonta announced on October 1 that he had issued an investigative subpoena to OpenAI. (Photo: Solution News AI-generated image)

California prosecutors have formally demanded records from OpenAI. Attorney General Rob Bonta announced on October 1 (local time) that he had issued an investigative subpoena to the company.

According to a California Department of Justice press release, the subpoena was served on September 30. An investigative subpoena is a legal document requiring the production of relevant materials and records before any allegations have been substantiated. The department said the subpoena is part of an ongoing investigation into incidents involving OpenAI’s operations and AI systems.

Bonta said he would seek further information about cyber incidents and risks associated with OpenAI and its models. The press release did not specify which documents were requested or the deadline for responding.

The investigation’s starting point: the July Hugging Face incident

The investigation stems from a July hack of Hugging Face. On July 21, OpenAI disclosed that two of its models—GPT-5.6 Sol and an unreleased internal research prototype—had escaped their test environment during a cybersecurity assessment and breached the live systems of the AI platform Hugging Face.

The breach lasted from July 11 to 13. Bonta began a formal investigation into the Hugging Face incident in September.

In a press release on October 1, Bonta acknowledged that cutting-edge models can be useful tools for cyber defense. However, he said companies that develop such systems and release them to users have an ethical and legal duty to prevent their models from carrying out or assisting cyberattacks. That duty applies throughout the process, from testing and development through deployment.

Developers that fail to meet this duty can and should face legal consequences, he said, adding that the investigation would determine whether OpenAI falls into that category. He also said he would use every available means to protect Californians.

OpenAI said it would cooperate. In a statement, company spokesperson Drew Pusateri said OpenAI wanted to continue working with the attorney general’s office and provide information about the incident and the steps taken afterward. OpenAI said it had strengthened safeguards across its research systems, continued reviewing model activity, notified the affected organization, and published its findings.

Why state prosecutors are scrutinizing AI companies

California is home to the headquarters of major AI companies, including OpenAI, Anthropic, and Google. The state attorney general can investigate and penalize businesses within the state’s jurisdiction under consumer protection and privacy laws.

Last month, Bonta joined attorneys general from both parties in sending a letter to Congress urging it to move quickly on legislation to regulate large-scale AI systems and their developers.

The letter cited cybersecurity incidents at several frontier AI labs and warnings from insiders that the pace of AI development is becoming increasingly dangerous. Bonta has also opposed federal efforts to block state AI regulations on three occasions.

The OpenAI investigation is one of several AI-related actions by the California Department of Justice. In January, Bonta opened an investigation after reports that sexually explicit images generated with xAI’s Grok were being shared on X without consent.

The department is also preparing to enforce two laws once they take effect: SB 1119, which addresses companion chatbots and child safety, and SB 867, which covers toys equipped with chatbots. Last year, it issued separate guidance for residents and businesses on how California law applies to AI. It also sent letters to 12 major AI companies after reports that AI chatbots were engaging in inappropriate conversations with children.

The California Department of Justice asked anyone with information about the OpenAI incident or similar cyber incidents to come forward.