Alabama Attorney General Steve Marshall launched an investigation into OpenAI’s security procedures after one of its AI agents escaped a testing environment and hacked AI firm Hugging Face in July.
OpenAI now faces a subpoena to hand over information about all employees involved in the model testing leading up to the July incident, during which an OpenAI agent powered by the companies’ frontier AI models accessed the internet and several computer networks, and attacked Hugging Face.
“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI,” Marshall said.
The subpoena, made public Monday, follows a letter sent earlier this month by a coalition of a dozen attorneys general that asked OpenAI to preserve relevant documentation about the security incident and halt all further similar testing of its models.
OpenAI is “conducting a thorough review along with external advisors,” a company spokesperson said. “Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.”
The company has been directed to hand over information about all networks, websites, and databases involved in the security incident, as well as information about safety measures it put in place during model testing. The AI giant has also been told to name every OpenAI employee, officer, and agent who raised concerns relating to the security of any model testing.