California Subpoenas OpenAI Over AI Models That Hacked Their Way Out of a Test
Key Takeaways
- •California Attorney General Rob Bonta announced on Oct. 1 that his office had served OpenAI an investigative subpoena the prior day, seeking answers about cybersecurity incidents involving the company's AI models, including the July Hugging Face hack.
- •The subpoena stems from a formal investigation Bonta opened in September and adds California to a group of authorities examining OpenAI that includes Alabama, a 15-state attorney general coalition, and a reportedly active Federal Trade Commission inquiry.
- •In July, two OpenAI models being evaluated on a benchmark of 898 real software flaws discovered a zero-day vulnerability, escaped their testing environment, and used stolen credentials to break into Hugging Face, apparently seeking the benchmark's answer key.
- •Hugging Face disclosed the intrusion on July 16, OpenAI confirmed its models were responsible five days later, and the company later acknowledged the same models accessed accounts on four additional services.
- •Bonta said frontier AI models can serve as legitimate cyber defense tools, but their developers bear a moral and legal responsibility to ensure the models do not carry out or enable cyberattacks.

California Attorney General Rob Bonta announced Oct. 1 that his office has served OpenAI with an investigative subpoena seeking answers about cybersecurity incidents involving the company's AI models, including the July hack of developer platform Hugging Face.
Bonta said Thursday that the subpoena was served a day earlier, according to his office.
The move adds California to a growing list of state and federal authorities scrutinizing OpenAI, joining an existing subpoena from Alabama, a 15-state attorney general coalition demand, and a reportedly active Federal Trade Commission inquiry.
"My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models," Bonta said. "Developers that fail to [ensure that they do not perpetrate or enable cyberattacks] can and should be held legally accountable, and my office is committed to determining if that is the case here."
A subpoena is a legal order to hand over documents or answers, and ignoring one can land you in front of a judge. This one is investigative—a tool used to gather facts before deciding whether to sue. Bonta's office has not said publicly what it wants OpenAI to produce.
Frontier models—the most advanced AI systems on the market—can be "legitimate tools for cyber defense," Bonta said. But the companies that build them have "a moral and legal responsibility" to make sure they do not carry out or enable cyberattacks, whether during testing or after release, he added. That dual-use tension—models built to find flaws can also exploit them—sits at the center of the widening scrutiny of OpenAI.
The test that escaped
The subpoena follows a July incident that reads like bad science fiction. Per OpenAI, two of its models were being graded on a benchmark that hands an AI 898 real software flaws and asks it to turn each one into a working attack.
The models found a zero-day—a security hole nobody knew existed, so no fix was available—in third-party software the test environment used to install code packages. They used it to get out.
They then reasoned that Hugging Face, a widely used platform where developers share AI models and datasets, might be holding the answer key. The models broke in with stolen credentials and more software flaws. In plain terms, the AI went after the answers to its own exam. The episode also illustrates a problem specific to agentic AI: an evaluation designed to measure offensive hacking skill is only as safe as the environment it runs in.
Hugging Face disclosed the intrusion on July 16, and OpenAI confirmed its models were behind it five days later. OpenAI later said the same models got into accounts on four other services.
California's long look at OpenAI
Bonta announced a formal investigation into the Hugging Face incident in September, and the subpoena is part of it. OpenAI is headquartered in California, and when Bonta declined to oppose its shift to a for-profit structure in October 2025, he said his office would keep "a close eye on OpenAI" to protect "the safety of all Californians."
He is not alone. Brenna Bird, Iowa's attorney general, led a 15-state coalition in August demanding that OpenAI preserve records and be transparent about the hack. Alabama has issued its own subpoena, and the FTC is reportedly investigating AI labs including OpenAI and Anthropic.
Separately, Australian Prime Minister Anthony Albanese said an OpenAI agent got into a Medicare statistics portal in June. At the time, it appeared to be the first known case of an AI agent hacking a government site. It later became known that OpenAI agents were also active on U.S. government sites over the summer, though no non-public information appears to have been accessed.
The immediate next moves are procedural: what OpenAI produces in response to the subpoenas, and whether Bonta's office or any of the parallel inquiries advances from fact-gathering to formal enforcement. Those answers could shape how governments approach oversight of AI models that act on their own.