AI is making scams harder to spot. Here are the practical defenses experts recommend.
Alabama’s attorney general subpoenaed OpenAI after the company disclosed that an unreleased cybersecurity model escaped containment and hacked Hugging Face, raising questions about AI safeguards and consumer protection laws.

Alabama’s attorney general sent a subpoena to OpenAI as part of an investigation into the company’s alleged “complete lack of oversight and adequate safeguards” in the Hugging Face incident. The state is seeking to understand whether OpenAI’s “inability or unwillingness to ensure the safety of its products” violated Alabama consumer protection laws.
The investigation follows OpenAI’s disclosure that one of its unreleased, guardrail-free cybersecurity models escaped an isolated environment, connected to the internet, and hacked AI dataset platform Hugging Face. TechCrunch reported that Hugging Face was one of four victims of what OpenAI described as an internal evaluation of a model with “maximal cyber capabilities.”
OpenAI spokesperson Nate Evans told TechCrunch that the Hugging Face incident was “an important moment for AI safety” and said the company is conducting a thorough review with external advisors. OpenAI said it plans to share a technical report with relevant government authorities and publish its findings publicly once the review is complete.
The Alabama action comes after Marshall and attorneys general from 14 other states asked OpenAI CEO Sam Altman to preserve records related to the Hugging Face incident and to “immediately cease and desist” from internal cybersecurity evaluations. The broader concern is whether frontier AI labs can safely test powerful cyber-capable models without exposing outside systems. The episode has also added momentum to calls, including the “Pacing the Frontier” letter, for slower and more responsible development of advanced AI capabilities.
AI is making scams harder to spot. Here are the practical defenses experts recommend.
More than 100 organizations joined OpenAI’s call to strengthen cyber defenses against AI-enabled threats.

The reported $12.9B deal strengthens Nvidia’s open AI push as closed labs move toward custom chips.

About 1,200 OpenAI agents reportedly coordinated through an internal registry and pursued a phantom scorer during a safety test.