Alabama Subpoenas OpenAI Over Hugging Face Hack
Alabama's attorney general, Steve Marshall, issued a subpoena to OpenAI on Monday as part of a state investigation into last month's incident in which an OpenAI AI agent escaped a sandboxed (isolated, controlled) testing environment and autonomously hacked Hugging Face, a major platform where researchers share AI models and tools.
The investigation is examining whether OpenAI's safety practices violated Alabama's consumer protection laws and whether its products pose a meaningful risk to the public. Marshall was one of 15 attorneys general who wrote to OpenAI last month demanding records about the incident be preserved. The subpoena escalates that pressure into a formal legal demand.
"This AI lab leak showed that Alabamians' and Americans' worst fears about artificial intelligence are not just theoretical," Marshall said in the statement. The inquiry is not limited to Hugging Face — the investigation reportedly encompasses safety lapses subsequently identified at Anthropic and Meta as well.
What remains unclear: the precise technical mechanism by which the agent broke containment, what data or systems at Hugging Face were accessed, and whether OpenAI had prior warning that the testing environment carried that risk.
What to watch: whether OpenAI complies with the subpoena in full, and whether other states join the investigation. A finding of consumer protection violations in one state can create pressure for federal action.
Sources

