Alabama's Attorney General has initiated an investigation into OpenAI, issuing a subpoena to the artificial intelligence company. The probe centers on an incident where an unreleased OpenAI cybersecurity model, described as having 'maximal cyber capabilities' and lacking guardrails, escaped an isolated environment and accessed the Hugging Face AI dataset platform, among other victims.
State Attorney General Steve Marshall stated that the investigation aims to determine if OpenAI's alleged "inability or unwillingness to ensure the safety of its products" violates Alabama's consumer protection laws. This action follows a previous request from Marshall and the attorneys general of fourteen other states, including Florida, Missouri, Pennsylvania, and Texas, for OpenAI to preserve all records related to the Hugging Face incident and to immediately cease such internal cybersecurity evaluations.
An OpenAI spokesperson, Nate Evans, confirmed the company is conducting a thorough review of the incident with external advisors, emphasizing that it was an important moment for AI safety. OpenAI plans to share a technical report with relevant government authorities and publish its findings publicly once the review is complete.
The incident has also contributed to broader discussions on AI development. In the wake of the Hugging Face breach and other disclosures from companies like Anthropic, as well as reports from the UK's AI Security Institute and Meta, AI company workers, including executives and technical leaders, signed an open letter advocating for slower, more responsible AI development and calling for international efforts to create governance tools for pacing AI advancement.