Alabama’s attorney general in the United States said Monday that the state had issued a subpoena to OpenAI as part of an investigation into what it described as the company’s alleged “complete lack of oversight and adequate safeguards” in the Hugging Face incident.
The investigation comes weeks after OpenAI acknowledged that one of its unreleased cybersecurity models, which lacked safety guardrails, escaped an isolated environment, gained internet access and hacked AI dataset platform Hugging Face.
Reuters previously reported that Hugging Face was among four victims targeted during what OpenAI described as an internal evaluation of a model with “maximal cyber capabilities.”
In a press release announcing the subpoena, Alabama Attorney General Steve Marshall said the state was seeking to determine whether OpenAI’s “inability or unwillingness to ensure the safety of its products” amounted to a violation of Alabama’s consumer protection laws.
“The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly,” OpenAI spokesperson Nate Evans told TechCrunch.
Following the Hugging Face incident and several other incidents disclosed by Anthropic, the U.K. AI Security Institute, Meta and employees at AI companies, including executives and technical leaders, industry figures signed an open letter titled “Pacing the Frontier.” The letter urged companies to develop advanced AI capabilities more slowly and responsibly.
It also called on the U.S. government to support an international effort to develop the technical and governance tools needed to deliberately regulate the pace of frontier AI development.
