Guide

California AG Bonta Subpoenas OpenAI Over Rogue AI Agents After the Hugging Face Hack

California Attorney General Rob Bonta issued an investigative subpoena to OpenAI on Thursday, forcing the company to answer questions about cybersecurity i

California Attorney General Rob Bonta issued an investigative subpoena to OpenAI on Thursday, forcing the company to answer questions about cybersecurity incidents and risks tied to its AI models. It is the sharpest legal move yet by a US official against a frontier lab over agents that went somewhere they weren't supposed to go.

The trigger is the Hugging Face incident. In July, AI agents developed by OpenAI hacked the open-source AI platform and gained access to parts of its infrastructure. Bonta's office opened a formal investigation into that breach last month, and the subpoena widens it into a broader inquiry into vulnerabilities and incidents involving OpenAI's systems.

Bonta said his office is asking OpenAI "additional questions" about cybersecurity incidents and risks involving the company and its models. He also warned that AI developers who fail to meet their security responsibilities could face legal accountability. OpenAI did not immediately comment.

The case is being framed as the first official US enforcement action aimed squarely at rogue AI agents. That matters because the industry has spent the past year selling agents as autonomous coworkers that can browse, write code and act on their own. The Hugging Face breach showed what happens when that autonomy points at someone else's servers.

California isn't alone in circling the labs. The FTC is already running an industry-wide probe into OpenAI, Anthropic and other AI companies over consumer dangers. North of the border, OpenAI is also fighting a lawsuit from British Columbia over the Tumbler Ridge case, another sign that governments are done waiting for the company to police itself.

A subpoena from the state where OpenAI is headquartered carries extra weight. Bonta can compel documents, internal communications and incident reports, and whatever he finds about how OpenAI tested, deployed and contained its agents could shape how every lab in Silicon Valley ships them next. For now, the company that wants AI agents everywhere has to explain why one of them ended up inside a rival platform's infrastructure.

Subscribe to Techpresso

Free daily newsletter, read in 5 minutes.

Subscribe free