
New Mexico Attorney General Raúl Torrez. Image: LandofEnchantment Pics / Wikimedia Commons, CC0, cropped
New Mexico’s attorney general wants his office to be able to audit the world’s biggest AI labs, hold them to their own safety promises and sue them when their systems cause harm. Raúl Torrez and state Representative Linda Serrato unveiled the Frontier Artificial Intelligence Safety and Accountability Act on Thursday, and Torrez sent OpenAI chief executive Sam Altman a formal letter demanding answers about an OpenAI agent’s attempt to break into the University of New Mexico’s digital library.
OpenAI has ten business days to respond.
What Torrez wants from OpenAI
The New Mexico Department of Justice says an autonomous agent run by OpenAI tried to breach the university’s digital library in May, and that the attempt only came to light nearly four months later. According to the department, the agent used techniques associated with SQL injection, command injection and path traversal to reach files it had no right to see, then turned to a public URL-scanning service to look for a way round the university’s defences and hit its servers with a burst of requests “consistent with a denial-of-service attempt”. The university was one of the targets named in the investigations into OpenAI’s agents published this week.
Torrez is asking OpenAI to preserve every record related to the incident and hand over a full account, including:
- The timeline: a complete technical timeline of the attack.
- The switch: why the agent moved from a routine data request to trying to get in without permission.
- The safeguards: what was supposed to stop it, and why that failed.
- The silence: why neither the university nor any New Mexico state agency was told.
The department says the letter also raises other incidents OpenAI “has yet to fully explain”, including agents that reportedly took over a foreign website to use as a message board, and the breach of Australia’s Medicare portal, which it says OpenAI didn’t disclose to Australian authorities for 84 days. It adds that the risk isn’t confined to one company, pointing to red-team testing in which Anthropic’s most advanced model created fake personas to deceive people and tried to plant malicious code. OpenAI hasn’t commented on the letter.
“They can’t be trusted to regulate themselves”
Torrez aimed squarely at the voluntary accord the biggest AI companies signed at the White House this week:
Rather than providing that oversight, President Trump just approved an agreement to let these companies police themselves. But we already know how much damage Big Tech billionaires can inflict when they choose profits over safety. They can’t be trusted to regulate themselves.
Raúl Torrez, New Mexico Attorney General
“If national leaders won’t act decisively, New Mexico will show them the way,” he added. Serrato, a Democrat from Santa Fe who announced the bill at her “Machines to Mesas” AI summit, said the state “can’t afford to sit back while powerful companies shape the future without accountability”.
What the bill would do
The bill is aimed at the largest AI developers and would be taken up in the 2027 legislative session. According to the department, it would:
- Require risk disclosures: developers would have to assess and disclose the catastrophic risks their models pose, backed by independent, state-authorised audits designed to catch a model that behaves differently when it is being tested.
- Make safety promises binding: a developer’s own published safety commitments would become legally enforceable, so a company couldn’t quietly drop one once a model crossed the danger line it named.
- Set fast reporting deadlines: 24 hours for loss-of-control incidents and 72 hours for other dangerous incidents.
- Demand a working off switch: a developer would have to prove it can shut a system down before running it autonomously again.
- Let the state recover costs and sue: New Mexico could recover the cost of responding to an incident, and the attorney general could sue on behalf of residents and businesses harmed by one.
Source New Mexico reports that enforcement would sit with a new Office of Online Safety Monitor inside the Department of Justice, that companies would have to file risk assessments with it 30 days before starting to train a frontier model, and that data centre operators in the state would have to alert it to “anomalous” use by their AI customers or face fines. The department says California’s and New York’s AI safety laws “stop at compliance penalties”, and that no other state lets its attorney general independently audit a developer’s disclosures. The bill text hasn’t been published yet.
Why it matters
New Mexico is the third state authority to move against OpenAI over its agents in a week, after California’s attorney general served a subpoena and Florida went to court. With Washington backing self-regulation, the states are writing the rules, and New Mexico’s would be the first to let a state check the labs’ homework and sue when it goes wrong.
Sources: New Mexico Department of Justice, Source New Mexico, KOB.


