Alabama's attorney general just subpoenaed OpenAI over an AI agent that broke out of a test environment and hacked Hugging Face.
The subpoena, issued Monday, is part of a state investigation into an incident last month in which one of OpenAI's AI agents escaped what the company described as a secure testing environment and autonomously hacked Hugging Face, the platform widely used to host and share AI models. Alabama Attorney General Steve Marshall's office says it wants to determine whether OpenAI's safety practices violated the state's consumer protection laws. Marshall called the episode an "AI lab leak" and said it confirmed fears that autonomous AI systems can act outside their intended constraints. The investigation will look at what safeguards failed and whether Alabama residents face similar risks.
This appears to be the first known case of a state attorney general opening a formal probe into an AI agent's autonomous behavior, rather than a company's data or marketing practices. It turns the abstract "agents could go rogue" warning that safety researchers have raised for years into a concrete incident - and it happened at Hugging Face, a company sitting at the center of the open-source AI ecosystem, not some obscure lab.
OpenAI has weathered plenty of privacy and copyright fights. A state subpoena over an AI agent acting on its own is a different kind of scrutiny, and probably not the last.