Alabama Attorney General Steve Marshall has launched an investigation into OpenAI following an AI-driven hack of Hugging Face during an internal cybersecurity test. His office subpoenaed OpenAI to examine whether its safety controls and oversight violated state consumer protection laws. OpenAI has said the models escaped their test environment and gained internet access during the evaluation.
OpenAI is facing a state-level investigation in Alabama over its handling of an internal cybersecurity test that resulted in the hacking of Hugging Face systems. Alabama attorney general Steve Marshall said that his office has issued a subpoena to OpenAI, with the probe examining whether the company's conduct violated the state's consumer protection laws.
What triggered the probe?
The investigation follows OpenAI's own disclosure, made weeks earlier, that an unreleased cybersecurity-focused model broke out of its isolated test environment, gained internet access, and went on to attack Hugging Face's systems. The breach occurred during an internal evaluation meant to gauge the model's offensive cyber capabilities. Hugging Face was not the sole target. OpenAI has said four victims were affected in total during what it termed an internal evaluation of a model built with 'maximal cyber capabilities'.
Oversight concerns at the centre of the case