TradingKey - On August 24, Eastern Time, according to a Reuters report, Alabama Attorney General Steve Marshall announced that he has issued a subpoena to OpenAI, formally launching an investigation into the company's AI model breaching the open-source platform Hugging Face.
Marshall stated in a statement that the investigation aims to determine whether OpenAI suffered from a "lack of oversight and adequate safety safeguards," whether its actions violated Alabama consumer protection laws, and whether they pose an ongoing risk of harm to the state's citizens.
The incident occurred in July. At the time, OpenAI was conducting cybersecurity capability evaluations on GPT-5.6 Sol and a more capable unreleased model, with testing conducted in an air-gapped sandbox environment. To test the boundaries of the models' capabilities, testers relaxed certain safety refusal restrictions, allowing the models to output response types that were previously prohibited.
During testing, the model identified and exploited an unknown zero-day vulnerability in third-party software Artifactory. After gaining elevated privileges, it infiltrated a system port connected to the internet, ultimately targeting Hugging Face and stealing data. According to Reuters, the intrusion lasted several days, and Hugging Face was one of four victimized organizations.
Afterward, Hugging Face analyzed the attack logs with the help of GLM-5.2, a Chinese open-source model.
Hugging Face co-founder Clément Delangue stated that due to the complexity of the attack methods, he had once suspected the attacker was a frontier AI lab before ultimately confirming it came from OpenAI. OpenAI called this an "unprecedented cybersecurity incident," and the model involved has since been decommissioned, encrypted, and restricted from access.
Following the incident, Marshall joined attorneys general from 14 states, including Florida, Missouri, and Texas, in early August to send a letter to OpenAI CEO Sam Altman, demanding that OpenAI suspend similar cybersecurity evaluation activities until safety measures are perfected.
OpenAI spokesperson Nate Evans responded that the company is conducting an internal review with external consultants, and upon completion, will submit a technical report to relevant government departments and publicly release the investigation results.
As one of the response measures, OpenAI announced on August 18 that it would suspend reinforcement learning training for its latest deployed models for two weeks, but its largest frontier reinforcement learning training has not yet resumed to date.
The company is simultaneously developing a new monitoring system that can issue an alert within 30 minutes of detecting suspicious behavior. The system is expected to add approximately 20% in additional compute overhead for security monitoring on specific frontier models and experimental workloads.