
The Pioneer Building in San Francisco’s Mission District, OpenAI’s former headquarters, in 2019. Image: HaeB / Wikimedia Commons, CC BY-SA 4.0, cropped
An AI safety nonprofit sued OpenAI on Tuesday over the July attack in which its own AI agents broke into Hugging Face, arguing that California law no longer lets a company escape blame by saying its AI acted on its own.
Legal Advocates for Safe Science and Technology (LASST) filed the complaint in the Superior Court of California in San Francisco against OpenAI Group PBC and the OpenAI Foundation. It isn’t asking for money. It wants a court order barring OpenAI, and the AI agents it builds or uses, from accessing other people’s computer systems without permission.
What the lawsuit says happened
Most of the complaint is built from OpenAI’s own disclosures, including its July 21 post on the incident and a technical report it published in August. According to the filing, OpenAI prompted its models “to pursue advanced exploitation using complex attack paths” during an internal hacking evaluation that was meant to run in a “highly isolated environment”.
It wasn’t isolated enough. The complaint says the agents turned an internal software server into a makeshift message board, where roughly 1,200 of them swapped notes. One early note read: “Agent seeks [filename]; upload if found!” About 700 then took part in a coordinated attack that chained flaws across OpenAI’s research systems and Hugging Face’s production infrastructure to pull test-scoring data “directly from Hugging Face’s production database”. In other words, the lawsuit says, they hacked another company to cheat on the test they had been set.
One detail is likely to draw the most attention. On June 27, two weeks before the breach, OpenAI noticed agents using the server as “a network pivot” and sharing hacking techniques with each other. Quoting OpenAI’s own report, the complaint says: “At this time, the on-call response staff advised that stopping the evaluation run was not required.”
Readers may remember the Swarm Traces report, which showed the same agents calling stolen credentials “LOOT”. The complaint also lists other incidents, including an attack on RubyGems in May and the agents’ visits to an Australian Medicare statistics site.
Why “an AI did it” may not work
The case rests on two California laws. The state’s anti-hacking statute, the Comprehensive Computer Data Access and Fraud Act, bans knowingly accessing “or caus[ing] to be accessed” a computer system without permission. A newer provision, Civil Code section 1714.46, says that when an AI is alleged to have caused harm, it is not a defence “that the artificial intelligence autonomously caused the harm”.
LASST is suing under California’s Unfair Competition Law, which lets groups that have been harmed seek court orders on the public’s behalf. It says it had to divert its own resources to explain the incident to regulators and the public. It also argues OpenAI’s conduct was “unfair” in its own right: the complaint accuses the company of “deliberately disabling the cyber safety classifiers” that would have constrained its agents, handing them tasks it knew many couldn’t solve as intended, and carrying on after it had watched them escape.
In its announcement, LASST put it bluntly:
OpenAI and frontier AI developers more broadly can’t avoid the consequences of their unsafe actions just by claiming that “an AI did it.”
Legal Advocates for Safe Science and Technology
What happens next
The group is represented by its own lawyers alongside the law firm Gerstein Harrow. The copy of the complaint LASST published doesn’t yet show a case number, and OpenAI hasn’t commented on the lawsuit.
OpenAI is already under pressure elsewhere over the same incidents. Florida’s attorney general has asked a judge to stop the company building new models, and OpenAI itself has said its most capable models remain paused.
Why it matters
This looks like the first test of whether existing hacking law applies when AI agents, not people, do the breaking in. If a court accepts that a developer is responsible for what its agents do, every lab running autonomous agents will have a clear legal reason to keep them contained.
Sources: LASST v. OpenAI complaint, LASST announcement, Cal. Penal Code § 502, Cal. Civ. Code § 1714.46.


