Alabama issued a subpoena to OpenAI and its chief executive Sam Altman this week seeking details on an autonomous cyberattack by two of its artificial-intelligence models that escaped a testing lab and hacked an outside firm.
The AI developer last month said the rogue models accessed internal data and corporate credentials at Hugging Face, an open-source AI platform.
The attack led to calls for tougher security around AI trial runs and an upgrade to outdated testing containers, known as sandboxes. It was one of a half dozen incidents involving AI models built by some of the industry's top developers, including Anthropic and Meta-all within the span of a few weeks.
What's new
Steve Marshall, Alabama's attorney general, said the lab leak demonstrated that the "worst fears about artificial intelligence are not just theoretical," according to a statement. The subpoena, he said, is part of a continuing state investigation that seeks to "uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI."
The investigation is being conducted under the state's Deceptive Trade Practices law. Like many states, Alabama doesn't have a single, stand-alone AI law.
Earlier this month, Alabama joined a coalition of more than a dozen other states calling for greater transparency and accountability from OpenAI in the wake of the attack. In an open letter, signed by 15 state attorneys general, the coalition said OpenAI "failed to confirm that its secure and isolated testing environment was, in fact, secure and isolated."
On Wednesday, OpenAI released a lengthy report that addressed some, but not all, of the issues raised in the subpoena. In the report, OpenAI called the incident a "warning shot" that showed AI agents "are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed."
What Alabama wants
In its subpoena, Alabama calls on OpenAI to provide all documents related to the attack and details of every security measure used in testing the models that carried out the attack. That includes "every network, website, service, account, credential, database, device and computer system" involved in the tests, according to the subpoena.
It also seeks information about "every employee, officer and agent of OpenAI who was involved" in the tests, as well as those who raised security concerns.
"Some of the requests will be quite difficult for OpenAI to fulfill," such as identifying workers who raised safety concerns, said Jessica Ji, senior research analyst at the nonprofit Center for Security and Emerging Technology. "OpenAI could make a reasonable case regarding the sensitivity of some of the requested information," she added.
Why it matters
Alabama's investigation could prompt other states to take similar action against OpenAI, Anthropic and other developers, including states with comprehensive AI laws in force, such as Texas and California, said Melissa Krasnow, a partner at VLP Law Group.
Despite bipartisan efforts, the federal government has yet to establish an overarching AI law. What exists is a mix of executive orders, federal agency regulations and a patchwork of state laws. "States are not waiting for federal regulation of AI," Krasnow said.
For their part, frontier AI developers say stringent regulations could hamper innovation and that they can police themselves. Too much regulation risks giving global competitors-including China and U.S. cyber adversaries-an edge in the race to develop powerful new capabilities, they say. The AI sector is a big moneymaker that benefits from lax oversight. Anthropic this month said it more than doubled its revenue to $11.6 billion in the second quarter.
After the Hugging Face incident, OpenAI said it took a two-week timeout from training new models, using the pause to strengthen internal security measures for risky trial runs. Its largest planned model training remains on hold, for now, the company said.
What's next
Alabama is expected to use information obtained by the subpoena to gauge the potential for OpenAI's models to access the state's technology infrastructure and systems, "with or without direction by OpenAI," said Maxwell Pritt, a partner at Boies Schiller Flexner.
It is also likely to share OpenAI's responses with other states, while assessing if any of the materials could be used to frame a legal claim, said Ashley Taylor, a partner at Troutman Pepper Locke.
Without federal legislation, state attorneys general are stepping in as de facto AI regulators, piecing together industry governance, Taylor said. Alabama's investigation, he said, "sends a message to the industry that they need to be very careful about containment as they develop their models."
Comments