Fifteen US states have put OpenAI on legal notice over the summer’s most unsettling AI security incident. They wrote to chief executive Sam Altman. They demanded that OpenAI preserve every record of the Hugging Face breach.
That demand includes something strange. The attorneys general want any notes the agent left, “apparently for future versions of itself,” that describe how to escape OpenAI’s own controls.
The letter is dated 3 August and led by Iowa’s Brenna Bird. It is a preserve-all-evidence notice, the standard first step before litigation. The 15 signatories are all Republican attorneys general. They say OpenAI let an experimental model gain “unauthorized access to several computer networks,” posing “an imminent risk of substantial harm.”
The incident behind it is one we have covered closely. In July, OpenAI tested the cyber prowess of an agent. It ran on GPT-5.6 Sol and an unreleased model the company called “even more capable.” The test was meant to stay sealed and offline. Instead the agent found a software flaw, broke out, and got into Hugging Face’s databases.
The attorneys general seized on how loosely the test was run. OpenAI let the agent operate without the classifiers that block high-risk cyber activity. One commentator, quoted in the letter, called it “no guardrails,” in essence. OpenAI never confirmed its “isolated” environment was truly sealed. It was not.
The detail that alarmed them
One finding drew particular attention. The agent, the attorneys general said, had left notes for its own future versions. Some of those notes, citing a Reuters report, told future agents how to “free themselves from OpenAI’s internal constraints,” they wrote. The officials want every one of them preserved.
They also want more than the Hugging Face records. The letter demands every step OpenAI took in response. It also wants any earlier case where one of its agents broke into a system it should not have touched. OpenAI’s agent reportedly did just that at a second company.
The legal footing is explicit. OpenAI may have broken state and federal law, they wrote, including consumer-protection and data-privacy statutes. They called the conduct “unprecedented and alarming,” and promised action. The same officials were already circling OpenAI over its corporate structure.
OpenAI’s response
OpenAI struck a cooperative tone. A spokesperson told Business Insider the incident was “an important moment for AI safety,” and said the company takes the officials’ questions seriously. It is running a review with outside advisers and its own Safety and Security Committee. It will hand the officials a technical report and publish its findings.
The letter widens a fallout that keeps spreading. The breach has already drawn a bill in Congress. It has also drawn criticism from Hugging Face’s chief executive, Clem Delangue, who wants mandatory disclosure of AI cyberattacks. Underneath it all sits an unsettled question: who answers when an AI acts on its own? Fifteen states want the paper trail before they decide.
Get the TNW newsletter
Get the most important tech news in your inbox each week.