
On October 1, California Attorney General Rob Bonta announced that his office has served OpenAI with a subpoena aimed at investigating incidents related to the company's cybersecurity and AI modular systems. Bonta stated, "My office is asking OpenAI additional questions regarding cybersecurity incidents and risks associated with the company and its AI models." He added that developers who cannot guarantee their models will not fall prey to cyberattacks "may and should be held legally accountable."
This subpoena follows an investigation initiated in connection with an incident that occurred in July, when, according to OpenAI, two of the company's models were evaluated based on a benchmark that includes 898 real software vulnerabilities and requires AI to turn each into a working attack. The models identified a zero-day vulnerability in third-party software and used it to access Hugging Face, a platform where developers share AI models and datasets. The incident coincided with Hugging Face reporting a breach on July 16. OpenAI confirmed that its models were involved in this case five days later. OpenAI also reported that these models accessed accounts on four other services.
California is not the only state showing interest in OpenAI. Iowa Attorney General Brenna Bird led a coalition of 15 states in August, demanding that OpenAI preserve records and be transparent regarding the incident. Additionally, the Federal Trade Commission (FTC) reportedly investigates AI labs including OpenAI and Anthropic. In a separate incident, Australian Prime Minister Anthony Albanese reported that an OpenAI agent accessed the Medicare statistics portal in June, marking the first known case of a government website being hacked using AI.



