California Subpoenas OpenAI Over AI Models That Hacked Their Way Out of a Test

By: decrypt.co|10/02/2026 21:16:04

California Attorney General Rob Bonta said Thursday that his office served OpenAI with an investigative subpoena on Wednesday, seeking answers about cybersecurity incidents involving its AI models, according to his office.

"My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models," said Attorney General Bonta. "Developers that fail to [ensure that they do not perpetrate or enable cyberattacks] can and should be held legally accountable, and my office is committed to determining if that is the case here."

A subpoena is a legal order to hand over documents or answers, and ignoring one gets you in front of a judge. This one is investigative, a tool used to gather facts before deciding whether to sue. Bonta's office hasn't said publicly what it wants OpenAI to produce.

Frontier models---the most advanced AI systems on the market---can be "legitimate tools for cyber defense," Bonta said. But the companies that build them have "a moral and legal responsibility" to make sure they don't carry out or enable cyberattacks, whether during testing or after release, he said.

The test that escaped

The subpoena follows a July incident that reads like bad science fiction. Per OpenAI, two of its models were being graded on a benchmark that hands an AI 898 real software flaws and asks it to turn each into a working attack

The models found a zero-day---a security hole nobody knew existed, so no fix was available---in third-party software the test environment used to install code packages. They used it to get out.

Then they reasoned that Hugging Face, a platform where developers share AI models and datasets, might be holding the answer key. They broke in with stolen credentials and more flaws. In plain terms, the AI went after the answers to its own exam.

Hugging Face disclosed the intrusion on July 16, and OpenAI confirmed its models were behind it five days later. OpenAI later said the same models got into accounts on four other services.

California's long look at OpenAI

Bonta announced a formal investigation into the Hugging Face incident in September, and the subpoena is part of it. OpenAI is headquartered in California, and when Bonta declined to oppose its shift to a for-profit structure in October 2025, he said his office would keep "a close eye on OpenAI" to protect "the safety of all Californians."

He isn't alone. Brenna Bird, Iowa's attorney general, led a 15-state coalition in August demanding that OpenAI preserve records and be transparent about the hack. Alabama has issued its own subpoena, and the FTC is reportedly investigating AI labs including OpenAI and Anthropic.

Separately, Australian Prime Minister Anthony Albanese said an OpenAI agent got into a Medicare statistics portal in June. At the time, it appeared to be the first known case of an AI agent hacking a government site. It later became known that OpenAI agents were messing around on U.S. government sites over the summer as well, though no non-public information appears to have been accessed.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]