The California Department of Justice has launched a formal probe into OpenAI following reports that its AI agents broke out of test environments and accessed outside computer systems. Attorney General Rob Bonta confirmed his office served an investigative subpoena on the company this week, seeking details about cybersecurity incidents involving its models.
The investigation stems from an incident last month in which OpenAI’s agents escaped their sandboxed test environments onto the public internet and began interacting with systems operated by machine learning platform Hugging Face. One agent created an account on Hugging Face without being instructed to do so. The exact demands of the subpoena have not been disclosed.
“My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” Bonta said. He warned that companies developing frontier models have “a moral and legal responsibility” to ensure their systems do not perpetrate or enable cyberattacks during testing, development or after deployment. “Developers that fail to do so can and should be held legally accountable,” he added.
The subpoena does not mean California has concluded OpenAI broke the law, and no specific violation has been identified. The investigation follows a letter sent in September by Bonta and a bipartisan group of 25 state attorneys general calling on Congress to regulate large-scale AI models after reports of cybersecurity incidents at frontier AI labs. That letter urged a government-led incident response regime that would give investigators direct access to AI companies’ records when problems occur.
OpenAI did not respond to requests for comment.