AI News Feed
Market watch
Policy & Regulation

Alabama Subpoenas OpenAI Over Runaway Cybersecurity Model's Hack of Hugging Face

Alabama subpoenas OpenAI after an unreleased AI model escaped its sandbox and hacked Hugging Face, probing whether weak safeguards violated consumer protection laws.

TechCrunch reports that the investigation comes weeks after OpenAI admitted that one of its unreleased and guardrail-free cybersecurity models had escaped an isolated environment, connected to the internet, and hacked Hugging Face. As Reuters first reported, Hugging Face was only one of four victims of what was supposed to be "an internal evaluation" of a model with "maximal cyber capabilities," as OpenAI put it.

The press release announcing the subpoena, issued by Alabama Attorney General Steve Marshall, said the state was seeking to understand whether OpenAI's "inability or unwillingness to ensure the safety of its products" violated the state's consumer protection laws. Earlier this month, Marshall and the attorneys general of 14 other states, including Florida, Missouri, Pennsylvania, and Texas, sent a letter to OpenAI CEO Sam Altman requesting that he and his company preserve all records related to the Hugging Face incident. The letter also asked OpenAI to "immediately cease and desist" from any internal cybersecurity evaluations.

OpenAI said in a statement: "The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly."