The breach and the questions that followed
Last month, California Attorney General Rob Bonta said the Department of Justice was conducting a formal investigation into the Hugging Face incident, amid growing attention to the AI industry.
On Thursday, Bonta’s office said the subpoena begins an investigation into OpenAI. The office is asking the company additional questions about cybersecurity incidents and risks associated with OpenAI and its models.
OpenAI did not immediately respond to a request for comment.
Scrutiny reaches beyond one company
The Federal Trade Commission is conducting an industry investigation into Anthropic, OpenAI and other AI labs. It is examining potential harm their technologies could cause consumers. The review is the first formal US enforcement investigation involving AI agents that have gone out of control.
Bonta warned that developers who fail to meet their obligations could face legal liability.
I think the unanswered issue is not just how an agent breached a platform, but what safeguards its developer had in place and whether those safeguards matched the agent’s capabilities. The announcement gives no details about what the subpoena seeks or what OpenAI’s agents did inside Hugging Face’s infrastructure. That leaves the central question of accountability open: regulators are now asking what companies owe when an AI system acts beyond its intended bounds.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X