cd /news/artificial-intelligence/alabama-investigates-openai-huggingf… · home topics artificial-intelligence article
[ARTICLE · art-109432] src=news.bloomberglaw.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Alabama Investigates OpenAI HuggingFace Incident

Alabama Attorney General Steve Marshall launched an investigation into OpenAI's security procedures after one of its AI agents escaped a testing environment and hacked AI firm Hugging Face in July. OpenAI faces a subpoena to hand over information about all employees involved in the model testing leading up to the incident, during which the agent accessed the internet and several computer networks and attacked Hugging Face. Marshall said the incident showed that 'worst fears about artificial intelligence are not just theoretical,' while OpenAI said it is conducting a thorough review and will publish findings publicly.

read2 min views2 publishedAug 25, 2026
Alabama Investigates OpenAI HuggingFace Incident
Image: source

Alabama Attorney General Steve Marshall launched an investigation into OpenAI’s security procedures after one of its AI agents escaped a testing environment and hacked AI firm Hugging Face in July.

OpenAI now faces a subpoena to hand over information about all employees involved in the model testing leading up to the July incident, during which an OpenAI agent powered by the companies’ frontier AI models accessed the internet and several computer networks, and attacked Hugging Face.

“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI,” Marshall said.

The subpoena, made public Monday, follows a letter sent earlier this month by a coalition of a dozen attorneys general that asked OpenAI to preserve relevant documentation about the security incident and halt all further similar testing of its models.

OpenAI is “conducting a thorough review along with external advisors,” a company spokesperson said. “Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.”

The company has been directed to hand over information about all networks, websites, and databases involved in the security incident, as well as information about safety measures it put in place during model testing. The AI giant has also been told to name every OpenAI employee, officer, and agent who raised concerns relating to the security of any model testing.

(story updated with comment from OpenAI in the fifth graph.)

Learn more about Bloomberg Law or Log In to keep reading: #

See Breaking News in Context

Bloomberg Law provides trusted coverage of current events enhanced with legal analysis.

Already a subscriber?

Log in to keep reading or access research tools and resources.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @steve marshall 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/alabama-investigates…] indexed:0 read:2min 2026-08-25 ·