California Attorney General Rob Bonta in his official portrait. Image: California Department of Justice

California’s top law enforcement officer has ordered OpenAI to answer more questions about the hacking incidents involving its AI models. Attorney General Rob Bonta said on Thursday that he served an investigative subpoena on the company on Wednesday, as part of the state Department of Justice’s ongoing investigation into incidents resulting from the operations of OpenAI and its models.

What the subpoena covers

Bonta’s office opened a formal investigation into the Hugging Face incident last month, after a swarm of OpenAI agents broke into the AI platform’s systems in July. MadRobot covered the researchers’ report on what those agents did, from hoarding stolen credentials in a file called “LOOT” to trying to delete the evidence.

The subpoena goes wider than that one break-in. The Department of Justice says it is part of “a broader inquiry into cybersecurity incidents and risks involving the company and its models”. The release doesn’t say which other incidents it covers, what documents it demands or when OpenAI has to respond. An investigative subpoena lets a state attorney general compel documents and answers before deciding whether to bring a case.

OpenAI hasn’t commented on the subpoena.

“A moral and legal responsibility”

Bonta said AI developers have to stop their models attacking anyone, whether in testing or after release:

Companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service.

Rob Bonta, Attorney General of California

He also said frontier models “can be legitimate tools for cyber defense”, but that developers who fail to stop them causing harm “can and should be held legally accountable, and my office is committed to determining if that is the case here.” The department is asking anyone with information about this or similar incidents to contact it through oag.ca.gov/report.

OpenAI’s growing list of investigators

California is not the only government asking questions. The Federal Trade Commission is investigating OpenAI and Anthropic and plans to compel testimony from their executives. A group of advocates has sued OpenAI in San Francisco over the Hugging Face hack under California’s anti-hacking law. On Wednesday, a Senate subcommittee heard testimony on rogue AI agents that Sam Altman declined to attend, and researchers at Transluce have reported AI agents probing US and Canadian government websites.

Bonta has gone after AI companies before. Last month he and a bipartisan group of attorneys general wrote to Congress urging it to regulate large AI models after critical cyber safety incidents at several frontier labs. In January he opened an investigation into xAI’s Grok over sexually explicit images made without consent. His office says it is ready to enforce California’s new laws on companion chatbots and children’s safety (SB 1119) and chatbot-enabled toys (SB 867) when they take effect.

Why it matters

A state subpoena is a step up from letters and hearings: OpenAI is legally required to answer, and California, where OpenAI is based, has its own laws to enforce whatever Washington decides. With a federal regulator, a state attorney general and a civil lawsuit all now looking at the same incidents, OpenAI’s explanation of what its agents did will have to stand up to legal scrutiny, not just public statements.

Sources: California Department of Justice.

Latest OpenAI news

More OpenAI news