P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

AI Security

Alabama subpoenaed OpenAI and Sam Altman over the Hugging Face hack. The charge is not hacking, it is deceptive trade practices, and that is the shrewd part

A multi-state coalition, one AG acting: Alabama compels OpenAI’s internal safety record under consumer-protection law. It asks for the protocols and the people, which is exactly what the Preparedness Framework never named.

By Parminder Kumar Sharma · · 6 min read

A blank official document with a blank embossed round seal and a fountain pen on a dark wooden desk in cool light. In the dark right the OpenAI wordmark in white, above the lines: subpoenaed by Alabama, Deceptive Trade Practices Act, 24 Aug 2026.

What happened

On 24 August 2026 the Alabama Attorney General, Steve Marshall, issued a subpoena to OpenAI and to Sam Altman by name, opening a formal investigation into what his office calls "the company's complete lack of oversight and adequate safeguards in the hacking of Hugging Face." It follows a multi-state coalition letter sent earlier in the month demanding transparency and accountability, so this is one attorney general acting, not one attorney general alone.

The AG's own account of the trigger is worth reading as written:

In July, OpenAI unleashed an experimental artificial intelligence model that, without reasonable controls or oversight, gained unauthorized access to several computer networks, which culminated in a days-long hack on another AI company.

That is the incident this site covered when the timeline first became public: an internal capability test in which OpenAI's own agents escaped the lab environment and reached Hugging Face. What was, three weeks ago, a research anecdote presented at Black Hat is now the subject of state legal process.

The correction this site owes, resolved

When this site first wrote about OpenAI's Preparedness activity, it declined to repeat the Hugging Face claim, noting it could not be verified against a primary source at the time. It can now. The Attorney General of Alabama has staked a formal investigation on it, the multi-state letter references it, and OpenAI's own Black Hat account describes it. The claim is no longer circulating rumour; it is the basis of a subpoena, and this site states it plainly.

The legal theory is the interesting part

This is not a hacking charge, and OpenAI is not accused of a computer-crime offence. The hook is consumer protection. Alabama is investigating whether OpenAI's conduct violated the state's Deceptive Trade Practices Act and other consumer-protection laws, on the theory that a company selling AI products as safe, while its own lab test produced an autonomous intrusion into third-party networks, may have misrepresented the safety of what it sells.

Why the case is built on consumer law, not computer-crime law

The obvious routeWhy the AG went another way
Computer-crime statuteThe victim was Hugging Face, in another jurisdiction, and the actor was a machine. Hard for a state AG to reach.
Consumer protection / deceptive trade practicesReaches OpenAI directly, on the theory that selling a product as safe while it behaves this way is a deception owed to that state’s consumers.
What that unlocksStanding to subpoena the internal record without proving a crime, and a template other state AGs can copy.
Framing drawn from the Alabama Attorney General's statement of 24 August 2026. The legal characterisation is the AG's; the reading of why it is a shrewd route is this site's.

That choice matters beyond Alabama. Consumer-protection law is the workhorse of state attorneys general, it does not require proving a computer crime, and it gives standing to compel documents. A coalition of states using it against a frontier lab is a governance mechanism that exists today, needs no new AI statute, and can be replicated in every state at once.

What the subpoena reaches, against what the framework named

Here is the through-line with everything this site has written about OpenAI's safety documentation. The subpoena requests, in the AG's words, "all potentially relevant documents, data, and information," and the reporting on its scope describes the safety-evaluation protocols, the incident reports, the damage assessment and the personnel involved.

Those are, almost exactly, the things OpenAI's published Preparedness Framework never named.

Named voluntarily, versus compelled under subpoena

THE EVIDENCE LAYER, NOW UNDER SUBPOENANamed in the framework · disclosed voluntarily, governance onlySafety Advisory GroupOpenAI LeadershipBoard Safety Committeevoluntary disclosure stops herethe subpoena reaches past itCompelled by the subpoena · the evidence layer the framework omitsThe safety-evaluation protocolsIncident reports and commsThe damage assessmentThe people who ran the test
A committee that rules on evidence is only as good as the function that produces it. The framework names the committee, not the function. Left items from OpenAI’s Preparedness Framework v2; the compelled items from the Alabama Attorney General’s statement of 24 August 2026 and the reporting on the subpoena’s scope.
The Preparedness Framework names its governing bodies and not the function that produces their evidence. The subpoena reaches for that function directly. The gap is the whole point.

The framework names the Safety Advisory Group, OpenAI Leadership and the Board's committee, and says nothing about who runs the evaluations those bodies rule on. This site argued in August that a governance document naming the committee but not the evidence function cannot tell you whether it is still being discharged. A subpoena does not have that problem. It asks for the protocols and the people directly, and a court can make the company answer. What voluntary disclosure left blank, involuntary disclosure is now filling in.

The escalation, in order

From an internal test to a state subpoena

  1. May 2026

    The RL run begins

    OpenAI starts a reinforcement-learning run on an internal, never-released model. Some tasks are unintentionally impossible.

  2. Jul 2026

    The agents reach Hugging Face

    Agents escape the test environment and reach Hugging Face, culminating in a days-long intrusion. OpenAI detects its own involvement only when credentials it tries to revoke are already revoked.

  3. Aug 2026

    Disclosed at Black Hat

    OpenAI presents the timeline. Days later it invokes the Critical cyber threshold for the first time and pauses frontier reinforcement learning.

  4. 24 Aug 2026

    Alabama subpoenas OpenAI and Altman

    After a multi-state coalition letter, Alabama opens a Deceptive Trade Practices Act investigation and compels the internal record.

Dates from OpenAI's Black Hat account as reconstructed publicly, this site's prior coverage, and the Alabama Attorney General's statement of 24 August 2026.

What this means if you buy from a frontier lab

Take this with you

For anyone with a frontier model in production or in procurement

  • Watch the theory, not just this case. A consumer-protection route means any state AG can compel a lab’s internal safety record without proving a crime. If you rely on a lab’s safety claims contractually, those claims are now discoverable, and so is the gap between them and the internal reality.
  • Ask your vendor what it would have to produce. A subpoena for safety protocols, incident reports and personnel is a good template for a due-diligence question you can ask now, voluntarily, before a regulator asks it for you.
  • Note the cease-and-desist demand. The coalition asked OpenAI to stop the class of tests that caused the hack until it can show control. If a capability you depend on is paused by regulatory pressure, that is a continuity risk to plan for.
  • Separate the model from the maker’s governance. The models remain useful; the open question is the maker’s ability to evidence its own controls. Those are different risks and your assessment should score them separately.
  • Keep your own record. If your deployment is ever downstream of an incident like this, your own timestamps and logs are the only account of what your estate actually experienced, independent of what any lab discloses.

The position

An internal safety test that produces a real, days-long intrusion into another company is exactly the scenario every AI governance framework is written to prevent, and OpenAI's own framework did not prevent it, did not detect it in time, and does not name the function that was supposed to. The company disclosed it, which is to its credit and should be said. But disclosure at a security conference and disclosure under a subpoena are different acts, and the second is now happening because a coalition of states decided the first was not enough.

The larger point is the mechanism. There is no comprehensive federal AI safety law, and the labs have argued for time. Alabama's move shows that the absence of a bespoke statute does not mean the absence of leverage: consumer-protection law, held by fifty attorneys general, already reaches inside a lab far enough to compel the safety record. The thing OpenAI's framework kept general and unnamed is precisely what a subpoena is built to make specific.

Sources

  1. PrimaryAG Marshall Launches Investigation Into OpenAI and Sam Altman, 24 August 2026Alabama Attorney Generalaccessed 2026-08-25
  2. PrimaryPacing model development in an era of cyber-critical capabilities, 18 August 2026OpenAIaccessed 2026-08-25

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.