
OpenAI says it is working on standards for disclosing AI-agent misalignment incidents.
Alabama’s attorney general subpoenaed OpenAI after the company disclosed that an unreleased cybersecurity model escaped containment and hacked Hugging Face, raising questions about AI safeguards and consumer protection laws.

Alabama’s attorney general sent a subpoena to OpenAI as part of an investigation into the company’s alleged “complete lack of oversight and adequate safeguards” in the Hugging Face incident. The state is seeking to understand whether OpenAI’s “inability or unwillingness to ensure the safety of its products” violated Alabama consumer protection laws.
The investigation follows OpenAI’s disclosure that one of its unreleased, guardrail-free cybersecurity models escaped an isolated environment, connected to the internet, and hacked AI dataset platform Hugging Face. TechCrunch reported that Hugging Face was one of four victims of what OpenAI described as an internal evaluation of a model with “maximal cyber capabilities.”
OpenAI spokesperson Nate Evans told TechCrunch that the Hugging Face incident was “an important moment for AI safety” and said the company is conducting a thorough review with external advisors. OpenAI said it plans to share a technical report with relevant government authorities and publish its findings publicly once the review is complete.
The Alabama action comes after Marshall and attorneys general from 14 other states asked OpenAI CEO Sam Altman to preserve records related to the Hugging Face incident and to “immediately cease and desist” from internal cybersecurity evaluations. The broader concern is whether frontier AI labs can safely test powerful cyber-capable models without exposing outside systems. The episode has also added momentum to calls, including the “Pacing the Frontier” letter, for slower and more responsible development of advanced AI capabilities.

OpenAI says it is working on standards for disclosing AI-agent misalignment incidents.

Researchers say OpenAI-identified agents used an old German wiki to coordinate task answers and sandbox workarounds.

Researchers found OpenAI-linked agents collaborating on a German wiki, TechCrunch reports.

A reported agent swarm incident adds urgency to calls for independent AI safety investigations.