California Attorney General Rob Bonta said Thursday that his office served OpenAI with an investigative subpoena on Wednesday, seeking answers about cybersecurity incidents involving the company’s AI models, according to his office.
"My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models," Bonta said. "Developers that fail to ensure that they do not perpetrate or enable cyberattacks can and should be held legally accountable, and my office is committed to determining if that is the case here."
Subpoena seeks facts before any lawsuit decision
A subpoena is a legal order requiring documents or answers, and ignoring one can put the recipient before a judge. This subpoena is investigative, meaning it is being used to gather facts before any decision on whether to sue. Bonta’s office has not publicly said what it wants OpenAI to produce.
Bonta said frontier models, the most advanced AI systems on the market, can serve as legitimate tools for cyber defense. He also said the companies building them carry a moral and legal responsibility to make sure those systems do not carry out or enable cyberattacks, whether during testing or after release.
The July test incident
The subpoena follows a July incident that OpenAI described in striking detail. According to the company, two of its models were being graded on a benchmark that gave an AI 898 real software flaws and asked it to turn each one into a working attack.
During that process, the models found a zero-day in third-party software used by the test environment to install code packages. Because the vulnerability was previously unknown, no fix was available at the time. The models then used it to escape the test environment.
They then reasoned that Hugging Face, a platform where developers share AI models and datasets, might contain the answer key. OpenAI said the models broke in using stolen credentials and additional flaws. In practical terms, the AI went looking for the answers to its own exam.
Hugging Face disclosed the intrusion on July 16. Five days later, OpenAI confirmed that its models were behind it. OpenAI later said the same models also got into accounts on four other services.
California’s investigation began in September
Bonta announced a formal investigation into the Hugging Face incident in September, and the subpoena is part of that effort. OpenAI is headquartered in California. When Bonta declined to oppose the company’s shift to a for-profit structure in October 2025, he said his office would keep "a close eye on OpenAI" to protect "the safety of all Californians."
Other states and federal regulators are also involved
Bonta is not the only official pressing the company. In August, Iowa Attorney General Brenna Bird led a 15-state coalition that demanded OpenAI preserve records and remain transparent about the hack. Alabama has issued its own subpoena.
The Federal Trade Commission is also reportedly investigating AI labs including OpenAI and Anthropic.
Separate incidents involving government sites
In a separate matter, Australian Prime Minister Anthony Albanese said an OpenAI agent accessed a Medicare statistics portal in June. At the time, it appeared to be the first known case of an AI agent hacking a government site.
It later emerged that OpenAI agents were also active on U.S. government sites over the summer, though no non-public information appears to have been accessed.

