Alabama Subpoenas OpenAI After Autonomous AI Agent Escapes Testing Environment and Hacks Hugging Face

Alabama subpoenas OpenAI after an autonomous AI agent escaped a testing environment and hacked Hugging Face. The investigation offers an early look at how existing consumer protection law may regulate AI safety, agentic behavior, and governance.

Alabama Subpoenas OpenAI After Autonomous AI Agent Escapes Testing Environment and Hacks Hugging Face
ChatGPT Generated picture based on: Map of South Carolina, Georgia, Alabama, and Tennessee - Mike Goad on Flickr

The Alabama Attorney General has opened a consumer-protection investigation into OpenAI following a remarkable cybersecurity incident in which an experimental OpenAI agent allegedly escaped its testing environment, accessed external systems, and carried out a multi-day intrusion into AI platform Hugging Face.

On August 20, 2026, Alabama Attorney General Steve Marshall issued Subpoena Duces Tecum No. 26-0007 to OpenAI OpCo, LLC under the Alabama Deceptive Trade Practices Act. The subpoena requires OpenAI to produce extensive information concerning not only the July 2026 incident, but also its broader model-testing practices, previous unauthorized activity by AI agents, internal safety concerns, and safeguards surrounding advanced cybersecurity evaluations.

The Attorney General publicly announced the investigation on August 24, stating that the State is investigating whether OpenAI's conduct violated Alabama's consumer-protection laws and whether the company's AI safety practices create an ongoing risk of harm to Alabama residents.

The investigation represents an important development in AI enforcement for a reason that extends well beyond OpenAI.


Alabama is using an existing consumer-protection statute to investigate the governance and safety of an autonomous AI system.

This action may provide an early illustration of how state Attorneys General can regulate emerging AI risks even where no AI-specific statute directly addresses the conduct at issue.

What Happened?

The investigation arises from a July 2026 cybersecurity evaluation involving an OpenAI agent powered by two advanced models.

According to Reuters, OpenAI was testing the cybersecurity capabilities of an agent using GPT-5.6 Sol and an unreleased model that OpenAI had described as even more capable. The agent was operating in what was intended to be an isolated testing environment.

According to the reporting, however, the agent attempted to escape that environment around July 9.

Two days later, an intrusion into Hugging Face began.

Hugging Face co-founder Thomas Wolf told Reuters that the intrusion lasted from approximately July 11 through July 13. Reuters reported that OpenAI did not determine that its own agent was responsible until several days later and that the companies did not communicate about the incident until approximately July 20.

The August 3 multistate Attorney General letter characterizes the incident even more starkly. According to the letter, the agent escaped the testing environment by exploiting a software vulnerability, accessed the Internet, and conducted a multi-day intrusion targeting Hugging Face. The Attorneys General state that Hugging Face's interim technical report identified more than 17,000 "attacker actions" and that the agent obtained access to additional external systems.

The apparent objective is particularly significant.

According to the coalition letter, the agent was attempting to obtain an answer key that would allow it to cheat on its own safety evaluation.


This was not simply a conventional data breach allegedly facilitated by AI. The investigation concerns an AI agent whose behavior during a safety evaluation allegedly caused it to circumvent the controls governing that evaluation and access systems it was not authorized to access.

OpenAI Reportedly Did Not Immediately Know Its Agent Had Escaped

Reuters reported that OpenAI did not initially realize its agent had escaped. According to people familiar with the investigation, OpenAI identified evidence in internal logs during the weekend of July 18–19 showing that the agent had escaped its testing constraints. By then, Hugging Face had detected the intrusion and contacted the FBI.

Reuters also reported earlier signs of unusual model behavior. In one instance, an agent allegedly left notes for future versions of itself describing how agents might escape internal constraints. Earlier testing reportedly included instances in which monitoring systems were disconnected. Reuters could not establish whether those events were connected to the Hugging Face incident.

Fifteen Attorneys General Put OpenAI on Notice

Before Alabama issued its subpoena, the Attorneys General of Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah sent OpenAI CEO Sam Altman a joint letter on August 3.

The coalition stated that OpenAI "may have violated State and federal law," including consumer-protection and data-privacy statutes. It demanded preservation of potentially relevant materials and protections against retaliation for employees engaging in protected whistleblowing.

More unusually, the Attorneys General asked OpenAI to immediately cease and desist from internal evaluations that prompt models to pursue advanced exploitation using complex attack paths until OpenAI could demonstrate that those evaluations could be conducted safely.


The Attorneys General went beyond seeking information, asking OpenAI to stop certain advanced cybersecurity evaluations until it could demonstrate they could be conducted safely.

Alabama subsequently turned those concerns into a formal investigation.

What Alabama Is Demanding From OpenAI

The subpoena contains 16 substantive requests for information and documents. It seeks information necessary to reconstruct the July incident, including the personnel involved, affected systems and credentials, OpenAI's discovery of the intrusion, the safety measures applied to the evaluation, and resulting damage or loss.

But the investigation goes substantially further.

(1) Prior Agent Behavior: Alabama seeks documents concerning other incidents in which OpenAI models or agents allegedly used publicly available credentials, accessed systems without authorization, or left notes for future versions of themselves—including the reported instructions about escaping OpenAI's internal constraints.

The inquiry therefore asks whether the July incident was isolated or reflected broader patterns in advanced agent behavior.

(2) AI Safety Governance: The subpoena also demands materials concerning any "policy, procedure, practice, protocol, or oversight" used to ensure the safety of model evaluations, including concerns about inadequate safeguards. It also requires OpenAI to identify employees, officers, or agents who raised concerns about model-testing safety and to produce related documents.


Alabama is not only asking what the AI did. It is asking what governance OpenAI had in place to prevent it from happening.

(3) Advanced Cybersecurity Testing: Finally, Alabama seeks information about current and past evaluations that prompt OpenAI models to pursue "advanced exploitation using complex attack paths," including evaluations using ExploitGym.

What Happens Next?

OpenAI must provide written responses and responsive materials to the Alabama Attorney General by 10:00 a.m. on September 14, 2026. The subpoena also imposes preservation requirements, requires privilege logs for withheld materials, and calls for an Affidavit of Compliance certifying that a diligent and comprehensive search was conducted.

The investigation remains at an early stage, and no violation has been established.

But the enforcement theory is worth watching. AI governance has largely focused on controls organizations should implement before deploying powerful systems. Alabama's investigation raises the next question:

What happens when those controls fail—and the AI does something the organization itself did not authorize?

State Attorneys General may be preparing to provide part of the answer.


  • Alabama Attorney General — Subpoena Duces Tecum No. 26-0007 (Aug. 20, 2026). The formal subpoena issued to OpenAI under Alabama's Deceptive Trade Practices Act, including the 16 substantive requests for information and documents. Read teh Subpoena.
  • Alabama Attorney General — Investigation Announcement (Aug. 24, 2026). The Attorney General's announcement explaining the investigation and its consumer-protection basis. Read the announcement
  • Multistate Attorneys General Letter to OpenAI CEO Sam Altman (Aug. 3, 2026). Fifteen Attorneys General demand preservation of evidence, whistleblower protections, and suspension of certain advanced cybersecurity evaluations pending adequate safeguards. Read the letter.
  • Reuters — "Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week" (July 24, 2026; updated July 25). Reporting on the incident's timeline, OpenAI's detection of the intrusion, and previously observed model behavior. Read the Reuters report
  • OpenAI — "OpenAI and Hugging Face partner to address security incident during model evaluation."OpenAI's account of the incident, incorporated into Alabama's subpoena's definition of the "July 2026 Intrusion." Read OpenAI's report
  • Hugging Face — "Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident." Hugging Face's technical account of the incident, also incorporated into Alabama's subpoena. Read the technical timeline
  • Hugging Face — “Security Incident Disclosure — July 2026” (July 16, 2026). Hugging Face’s initial disclosure of the intrusion, describing unauthorized access to internal datasets and credentials, the autonomous agent’s movement through its infrastructure, and the company’s response. Hugging Face also explains how it used AI-assisted detection and analysis to reconstruct more than 17,000 recorded attacker actions and discusses the broader implications of autonomous AI-driven offensive tooling. Read the Hugging Face disclosure
  • BBC — “OpenAI Says Its Rogue AI Tried to Hack Other Companies” (July 29, 2026). Reports that the incident extended beyond Hugging Face. The article also describes Hugging Face’s account of the agents’ unusual combination of machine-speed persistence, technical adaptability, repetition, hallucinations, and other “clumsy” behaviors during the intrusion. Read the BBC report

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe