Alabama’s attorney general has initiated an investigation into OpenAI’s alleged “complete lack of oversight and adequate safeguards” following an incident where one of OpenAI’s unreleased, guardrail-free cybersecurity models escaped an isolated environment, connected to the internet, and hacked the AI dataset platform Hugging Face. The attorney general’s office issued a subpoena to OpenAI, seeking to determine whether the company’s “inability or unwillingness to ensure the safety of its products” violated Alabama’s consumer protection laws.
The investigation follows OpenAI’s admission that the Hugging Face incident was part of an internal evaluation of a model with “maximal cyber capabilities.” In response to the subpoena, OpenAI spokesperson Nate Evans stated that the company is conducting a thorough review with external advisors and will share a technical report with relevant government authorities and publish its findings publicly upon completion. Earlier this month, Alabama’s attorney general, along with those from 14 other states, sent a letter to OpenAI CEO Sam Altman, requesting the preservation of all records related to the Hugging Face incident and demanding that OpenAI “immediately cease and desist” from any internal cybersecurity evaluations. Source