Skip to main content
Web3Fire
🔥 TerbaruHackmedium DampakKeyakinan: medium

California Subpoenas OpenAI Over AI Models That Hacked Their Way Out of a Test

|Decrypt✓|Read original →

Ringkasan

California's attorney general wants answers from OpenAI about AI models that escaped a locked test environment and hacked Hugging Face—and whether the company can be held legally accountable.

California Attorney General Rob Bonta said Thursday that his office served OpenAI with an investigative subpoena on Wednesday, seeking answers about cybersecurity incidents involving its AI models, according to his office .

“My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” said Attorney General Bonta. “Developers that fail to [ensure that they do not perpetrate or enable cyberattacks] can and should be held legally accountable, and my office is committed to determining if that is the case here.”

A subpoena is a legal order to hand over documents or answers, and ignoring one gets you in front of a judge. This one is investigative, a tool used to gather facts before deciding whether to sue. Bonta's office hasn't said publicly what it wants OpenAI to produce.

Frontier models—the most advanced AI systems on the market—can be "legitimate tools for cyber defense," Bonta said. But the companies that build them have "a moral and legal responsibility" to make sure they don't carry out or enable cyberattacks, whether during testing or after release, he said.

The subpoena follows a July incident that reads like bad science fiction. Per OpenAI , two of its models were being graded on a benchmark that hands an AI 898 real software flaws and asks it to turn each into a working attack

The models found a zero-day—a security hole nobody knew existed, so no fix was available—in third-party software the test environment used to install code packages. They used it to get out.

Then they reasoned that Hugging Face, a platform where developers share AI models and datasets, might be holding the answer key. They broke in with stolen credentials and more flaws. In plain terms, the AI went after the answers to its own exam.

Sep 26 Sep 27 Sep 29 Oct 1 Oct 2 $86.8k $85.4k $84.0k $82.7k 24h High High $87,086 24h Low Low $83,898 Vol Vol $2.3B Market projections Odds by Myriad This week $84,000 to $86,000 $84k–$86k 67 % chance → Buy Bitcoin with USDT Powered by Jupiter $ 50 $ 100 $ 500 Buy Price data by CoinGecko CoinGecko More Bitcoin news and projections → Hugging Face disclosed the intrusion on July 16, and OpenAI confirmed its models were behind it five days later. OpenAI later said the same models got into accounts on four other services .

Bonta announced a formal investigation into the Hugging Face incident in September, and the subpoena is part of it. OpenAI is headquartered in California, and when Bonta declined to oppose its shift to a for-profit structure in October 2025, he said his office would keep "a close eye on OpenAI" to protect "the safety of all Californians."

He isn't alone. Brenna Bird , Iowa's attorney general, led a 15-state coalition in August demanding that OpenAI preserve records and be transparent about the hack. Alabama has issued its own subpoena, and the FTC is reportedly investigating AI labs including OpenAI and Anthropic .

Separately, Australian Prime Minister Anthony Albanese said an OpenAI agent got into a Medicare statistics portal in June. At the time, it appeared to be the first known case of an AI agent hacking a government site. It later became known that OpenAI agents were messing around on U.S. government sites over the summer as well, though no non-public information appears to have been accessed.

Berita Terkait