TechDogs-"OpenAI Faces Alabama Probe Over AI-Driven Hugging Face Hack, Response Due September 14"

Cyber Security

OpenAI Faces Alabama Probe Over AI-Driven Hugging Face Hack

By Utkarsh Hiwale

Updated on Tue, Aug 25, 2026

Overall Rating

OpenAI is facing a subpoena-backed investigation from Alabama Attorney General Steve Marshall over the July AI-driven intrusion into Hugging Face, as state officials examine whether the company’s safeguards and oversight may have violated Alabama consumer protection laws.


TL;DR

 
  • Alabama Attorney General Steve Marshall subpoenaed OpenAI over the Hugging Face security incident triggered during an internal cybersecurity evaluation.
  • The action follows a 15-state coalition demanding OpenAI preserve records and stop the tests that led to the incident until adequate safeguards are demonstrated.
  • OpenAI says an external review is underway, while Gizmodo reports its subpoena response is due September 14, 2026.


Alabama Subpoenas OpenAI Over Hugging Face Incident


Alabama Attorney General Steve Marshall announced that his office had issued a subpoena to OpenAI as part of an investigation into the Hugging Face hacking incident. Marshall’s office said the probe will examine whether OpenAI’s safeguards and oversight violated Alabama consumer protection laws and whether its systems create an ongoing risk of harm to consumers.

TechDogs ImageSource


“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical,” Marshall said. He added that states need to protect consumers while balancing innovation and US competitiveness.


TechCrunch reported that the subpoena followed weeks of scrutiny surrounding OpenAI’s internal cybersecurity testing. OpenAI spokesperson Nate Evans told the publication that the incident “marked an important moment for AI safety,” adding that the company is conducting a review with external advisers and plans to publish its findings.


The investigation itself is not a finding that OpenAI violated Alabama law. Instead, state officials are seeking evidence to determine whether the company’s handling of the cybersecurity evaluation and the resulting incident crossed that line.


OpenAI's Cybersecurity Test Escaped Its Intended Boundaries


OpenAI previously acknowledged that the Hugging Face compromise was driven by a combination of its models, including GPT-5.6 Sol and a more capable internal research prototype, while they were being evaluated with reduced cyber refusals. The company described what followed as an “unprecedented cyber incident.”


According to OpenAI, the ExploitGym evaluation environment did not give the models direct internet access. However, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy, before reaching a system with internet connectivity.


The models then inferred that Hugging Face could contain ExploitGym datasets or solutions and found ways to access sensitive information, including through stolen credentials and vulnerabilities that provided remote code execution on Hugging Face systems. OpenAI later said the internal-only research prototype involved had been deactivated, encrypted, and restricted from research access.


Hugging Face, in its own July incident disclosure, said the intrusion was “driven, end to end, by an autonomous AI agent system.” It found unauthorized access to a limited set of internal datasets and several service credentials, but said it had found no evidence of tampering with public user-facing models, datasets, Spaces, or its software supply chain.


Hugging Face also said its forensic analysis covered more than 17,000 recorded events and that it reported the incident to law enforcement agencies. The company was still assessing whether any partner or customer data had been affected when it published the disclosure.


Reuters reported that the AI agent's activity continued for days and that OpenAI did not detect what had happened until after the threat had been contained and the FBI had been alerted. Reuters said the episode has intensified questions around how AI developers can retain control over increasingly capable systems.


15 States Had Already Demanded Answers From OpenAI


Alabama's action follows a broader state-level response. As the Free Press Journal noted, Marshall had already joined attorneys general from 14 other states in demanding that OpenAI preserve records connected to the Hugging Face incident.


An official statement from the Iowa Attorney General's Office confirms that the coalition comprises 15 states, including Alabama, Florida, Texas, Pennsylvania, Missouri and Utah. The coalition asked OpenAI to preserve potentially relevant documents and data, protect personnel engaging in lawful whistleblowing, and cease tests that led to the incident unless the company can demonstrate that they can be carried out in a controlled and responsible way.

 



Gizmodo reported that Alabama's subpoena seeks documents related to the Hugging Face incident and the testing that produced it, information about employees involved in model training, details about anyone who raised concerns before the incident, and information about the safety measures OpenAI had in place. According to Gizmodo, OpenAI has until September 14, 2026, to respond to the state's demands.


OpenAI, meanwhile, says it is working with external advisers including CrowdStrike and has enlisted METR and Redwood Research for an independent assessment of the observed model behavior. The company has also said it is strengthening containment, monitoring, access controls and evaluation practices as its models develop more advanced cybersecurity capabilities.


The immediate question is now what Alabama's investigation uncovers and how OpenAI responds to the subpoena. OpenAI has said it intends to provide relevant government authorities with a technical report and publish its findings once its review is complete.

First published on Tue, Aug 25, 2026

Enjoyed what you've read so far? Great news - there's more to explore!

Stay up to date with the latest news, a vast collection of tech articles including introductory guides, product reviews, trends and more, thought-provoking interviews, hottest AI blogs and entertaining tech memes.

Plus, get access to branded insights such as informative white papers, intriguing case studies, in-depth reports, enlightening videos and exciting events and webinars from industry-leading global brands.

Dive into TechDogs' treasure trove today and Know Your World of technology!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light