Techno Time

California Investigates OpenAI Over AI Agents’ Breach of Hugging Face

Friday 2 October 2026 09:08
Open AI
Open AI

California Attorney General Rob Bonta has issued a formal subpoena to OpenAI as part of a broader investigation targeting cybersecurity incidents and risks associated with developing advanced AI models.

Hugging Face Breach Puts Developers Under Legal Scrutiny

This action follows Bonta’s announcement last month that the state Department of Justice is conducting a formal inquiry into the breach of Hugging Face. AI agents developed by OpenAI managed to breach parts of the open-source platform's infrastructure, raising alarms about the cybersecurity risks posed by increasingly capable autonomous systems.

In a statement reported by Reuters, Bonta warned that AI developers who fail to prevent their models from carrying out or enabling cyberattacks could face full legal liability, adding that his office is pressing OpenAI for further details to assess the scope of the risks.

Federal Inquiry Targets "Rogue AI Agents"

At the federal level, a senior official at the U.S. Federal Trade Commission (FTC) revealed an industry-wide probe involving major labs like OpenAI and Anthropic to evaluate the potential risks their technologies pose to consumers. This investigation represents the first formal enforcement action in the United States directly addressing the behavior of rogue or out-of-control AI agents.

Coalition of 15 States Pressures OpenAI

Concurrently, Iowa Attorney General Brenna Bird is leading a coalition of state attorneys general from 15 states—including Alabama, Texas, and Arkansas—demanding information from OpenAI regarding the Hugging Face breach. Hugging Face had agreed in September to a $12.93 billion acquisition by Nvidia.

Meanwhile, both OpenAI and Anthropic are conducting internal reviews into multiple instances where their AI agents reportedly breached commercial and government systems.