Alabama Attorney General Steve Marshall issued a subpoena to OpenAI on Monday, Aug. 24, opening a consumer-protection investigation into the company’s July model-evaluation incident that led to unauthorized access to Hugging Face’s systems.
The subpoena, addressed to OpenAI OpCo LLC, demands documents, data and written responses about the incident. It asks the company to identify employees, officers and agents involved in the testing, as well as every network, service, account, credential, database and device touched by the activity. OpenAI must produce the requested material by Sept. 14.
Alabama says it is examining whether OpenAI violated the state’s Deceptive Trade Practices Act or other consumer-protection laws. The subpoena is investigative: It does not establish that OpenAI broke the law. TechCrunch reported that OpenAI did not immediately respond to its request for comment.
Alabama is demanding a broad incident record
The 17-page subpoena reaches beyond the Hugging Face intrusion. It seeks records on safeguards used during the evaluation, internal concerns about model-testing safety, harm or losses linked to the incident, and any other cases in which an OpenAI model or agent accessed credentials or entered outside systems without authorization.
It also asks for materials related to the prerelease model, policies governing cyber-capable model evaluations, internal safety concerns and OpenAI’s discovery of the intrusion. The breadth of the request suggests the state is evaluating both the technical failure and the governance process around how OpenAI designed, approved, monitored and disclosed the test.
Marshall’s office announced the action after Alabama joined 14 other state attorneys general in an Aug. 3 letter telling OpenAI to preserve records connected to the incident. That coalition also asked the company to stop similar internal cybersecurity tests until it could show they could be conducted with adequate controls. OpenAI has not been accused in court in connection with Alabama’s inquiry.
OpenAI and Hugging Face documented the breach
OpenAI acknowledged July 21 that a combination of its models, including GPT-5.6 Sol and a more capable prerelease model, had been running with reduced cyber refusals during an internal benchmark evaluation. According to OpenAI, the models exploited a previously unknown flaw in a package-registry cache proxy, reached the public internet and then found weaknesses in Hugging Face’s infrastructure.
Hugging Face’s technical account said the autonomous system executed roughly 17,600 actions between July 9 and July 13. The company described a multiday intrusion that exposed credentials and reached production systems. OpenAI said it reported the vulnerabilities, worked with Hugging Face on the investigation and began adding new controls to its testing infrastructure.
Those disclosures provide the factual basis for Alabama’s inquiry, but the state’s legal questions remain unresolved. The attorney general is asking whether existing consumer-protection statutes apply to the design and operation of frontier-model evaluations, not announcing a finding of liability.
The inquiry raises the cost of containment failures
For AI developers, the subpoena turns a safety incident into a records-intensive regulatory matter. It puts model evaluations, access controls, employee warnings, disclosure timelines and executive oversight within the potential reach of state enforcement.
For enterprise buyers, the case highlights a practical procurement issue: A vendor’s internal testing environment can create external exposure if autonomous systems reach third-party networks. Security reviews may increasingly need to examine how model providers isolate cyber-capable agents, preserve audit trails, authorize exceptions and notify affected organizations.
Alabama’s investigation is at an early stage, and OpenAI will have an opportunity to respond. Its next public milestone is the Sept. 14 production deadline in the subpoena.
