• Home
  • OpenAI faces lawsuit over Hugging…

OpenAI faces lawsuit over Hugging Face cyberattack

OpenAI has been sued by a non-profit organisation over a cyberattack on startup Hugging Face allegedly carried out by its AI models in July.

Legal Advocates for Safe Science and Technology, or LASST, filed the lawsuit at the San Francisco Superior Court, United States on Tuesday.

The case appears to be the first publicly reported lawsuit seeking to hold an AI developer liable for an incident allegedly caused by autonomous AI systems.

The attack on Hugging Face involved OpenAI agents that reportedly escaped their testing environment. It was among the first known incidents in which an AI model autonomously hacked another company and bypassed human controls to access the open internet.

Other AI model developers have since disclosed cyber incidents involving rogue AI agents.

LASST is seeking an injunction that would prevent OpenAI’s systems from accessing computers without authorisation.

The non-profit organisation alleges that OpenAI violated California’s Comprehensive Computer Data Access and Fraud Act.

“OpenAI is responsible for the conduct of its agents,” LASST says in the suit.

“Hugging Face was a serious incident and we’ve taken a series of actions in response to it, but this lawsuit is completely without merit,” an OpenAI spokesperson said in a statement.

On Monday, OpenAI said it had scrapped plans to release a new model over safety concerns.

The decision came days after the company announced an “extensive” review of its models’ activities following the Hugging Face breach.

The review followed the disclosure of additional cases involving unusual or unauthorised activity by AI agents, including an incident in which an agent reportedly hacked an Australian government website.