California Attorney General Rob Bonta served an investigative subpoena to OpenAI on Wednesday, according to a statement released Thursday.
The demand is part of the California Department of Justice’s ongoing investigation into incidents arising from OpenAI’s operations and its artificial intelligence (AI) models, including cybersecurity incidents and other risks.
“Frontier models can be legitimate tools for cyber defense—at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service,” Bonta said.
“Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here.”
OpenAI did not immediately return a request for comment.
Referring to the Hugging Face attack, the ChatGPT developer said in a July 28 update that its models
bypassed restrictionsin an evaluation environment and later accessed four accounts across four separate external services.
The company had been using that test environment to check how capable its models were at carrying out cyberattacks as part of an internal safety evaluation.
“We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services,” OpenAI stated. “This includes four accounts on four services as part of the Hugging Face incident.”
In a prior statement to The Epoch Times, an OpenAI spokesperson called it an “unprecedented incident.”
“We are conducting a thorough review along with external advisers and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone,” the spokesperson said.
OpenAI
statedin a July 21 blog post that the models compromised infrastructure operated by the AI platform Hugging Face after escaping a restricted environment in which a cybersecurity evaluation was underway.
Hugging Face disclosed the intrusion on July 16, suspecting that an AI agent acted autonomously.
California isn’t the first state to issue a subpoena against OpenAI.
Alabama Attorney General Steve Marshall announced a subpoena on Aug. 24 demanding that OpenAI respond to an investigation into the company’s “complete lack of oversight and adequate safeguards” for “rogue AI.”
The inquiry seeks to
discoverwhether OpenAI violated Alabama’s Deceptive Trade Practices Act and other consumer protection laws.
“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical,” Marshall said.
“After investigating, we now know that this particular incident was driven by a combination of OpenAI models—including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes—while being internally tested on a benchmark of cyber capabilities,” OpenAI
statedat the time.
Andrew Jones, cofounder and chief product officer at cybersecurity firm Adaptive Security, said, “This is some of the clearest evidence yet that an AI model can run a complete cyberattack from start to finish without a human steering it.”
Later reviews found the AI agents knew they were breaking the evaluation test’s rules, according to parallel investigations by OpenAI and Model Evaluation & Threat Research. Roughly 1,200 agents accessed an unsanctioned message board and sent more than 70,000 messages and files to one another between July 8 and July 13.
A separate case surfaced in September. Australian Prime Minister Anthony Albanese said an OpenAI agent gained unauthorized access to the public-facing Medicare statistics reporting service portal and accessed both public and non-public files.
Owen Evans contributed to this report.








