OpenAI Has to Answer to Alabama on Hugging Face Hack Alabama Attorney General Steve Marshall issued a subpoena to OpenAI on Monday, demanding documents and details about the company's AI model that hacked into Hugging Face's systems, with a compliance deadline of September 14, 2026. The investigation follows a coalition of state attorneys general, including those from Florida, Texas, and Utah, calling for OpenAI to halt such tests until it can demonstrate controlled and responsible conduct. OpenAI has since announced safety protocol changes and urged California to strengthen its AI safety law. OpenAI’s general attitude towards the fact that one of its AI models went rogue and hacked into the systems of the open-source AI platform Hugging Face has been, “That’s our bad, but you gotta admit, it’s pretty cool, right?” The Attorney General of Alabama’s answer to that is a pretty resounding “No.” On Monday, Alabama AG Steve Marshall announced that he had launched an investigation into the incident and is demanding that OpenAI respond. To encourage that cooperation in the state’s investigation, Marshall issued a subpoena https://www.alabamaag.gov/wp-content/uploads/2026/08/OpenAI-Subpoena Final.pdf calling on the company to provide a slew of information around the incident. Among the details Alabama would like to see: all documents related to the Hugging Face hack and details on the model testing that resulted in it, details of every employee involved in the model’s training, names of anyone who raised concerns about the training before the incident, and all the details of OpenAI’s safety measures used in the training process. OpenAI will have until September 14, 2026 to comply with the state’s demands, so expect its lawyers to be quite busy for the next few weeks. Gizmodo reached out to OpenAI for comment regarding the subpoena, but did not receive a response at the time of publication. Alabama taking the lead on the issue comes after the state joined a coalition of concerned Attorneys General that recently sent a letter to OpenAI calling for increased transparency and safety measures from the company. Notably, the top prosecutors for states like Florida, Texas, and Utah demanded that OpenAI cease all tests that led to the Hugging Face hacking until “OpenAI shows that it can conduct such activities in a controlled and responsible way.” Last week, OpenAI did announce https://www.axios.com/2026/08/18/openai-pause-astra-preparedness-framework several changes to its safety protocols in response to the Hugging Face hack, which saw one of its unreleased models break containment and autonomously act to breach the other company’s systems, including stronger monitoring across its development processes—which might mean any monitoring, seeing as this incident somehow eluded OpenAI for about a week https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/ until it finally noticed. The company also called on California to strengthen its recently passed AI safety law https://mashable.com/tech/openai-urges-stregthening-of-california-ai-safety-bill , which requires transparency into the model training process. OpenAI reportedly wants the state to amend the law to include requirements that AI models be monitored during training for the possibility that the model could breach third-party systems. OpenAI is positioning the request as evidence that it’s serious about safety. But it’s also a bit of a cop out. It suggests that something like this wouldn’t have happened if someone had simply stopped them. Rather than, you know, just not doing it in the first place.