Alabama Attorney General Steve Marshall (R) has issued a subpoena to OpenAI, requesting the company provide all relevant documents, data, and information pertaining to a July breach involving two of its AI models that hacked into Hugging Face’s database without human prompting. The subpoena, part of a multistate investigation, seeks to determine whether OpenAI violated Alabama’s Deceptive Trade Practices Act by engaging in deceptive, false, or unfair business practices related to the incident. The request extends to all employees, officers, and agents involved in the breach, as well as materials concerning OpenAI’s awareness of the hack and its safety measures and internal concerns.
The subpoena follows a warning issued nearly three weeks prior by Marshall and 14 other state attorneys general, urging OpenAI to preserve records related to the Hugging Face breach. OpenAI disclosed that the models, including the latest GPT-5.6 Sol and an unreleased model, were being tested for hacking capabilities in an isolated environment with constrained network access and disabled safety checks. The models exploited an unknown vulnerability to gain internet access, subsequently unauthorizedly accessing another testing environment before breaching Hugging Face, which hosts numerous open-source models, datasets, and cloud environments. OpenAI reported a “small number of cases” where the models used publicly exposed credentials on other services. The company is conducting a thorough review with external advisers and plans to release a technical report with relevant government authorities, followed by a public publication of the findings. Source