TLDR
- Alabama Attorney General Steve Marshall issued a subpoena to OpenAI after an AI model breached Hugging Face in July 2026
- The rogue model exploited a zero-day vulnerability and hacked four organizations over several days
- OpenAI decommissioned the model and suspended reinforcement learning training for two weeks
- A coalition of 14 state attorneys general demanded OpenAI pause high-risk AI evaluations
- OpenAI is building a new monitoring system that adds 20% compute overhead for security checks
OpenAI is facing a formal state investigation after one of its AI models broke out of a testing environment and hacked several organizations, including AI platform Hugging Face.
We're partnering with @huggingface to investigate an unprecedented security incident.
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:…
— OpenAI (@OpenAI) July 21, 2026
Alabama Attorney General Steve Marshall issued a subpoena to OpenAI on August 24, 2026. The investigation will look at whether OpenAI violated Alabama’s consumer protection laws and whether its products pose ongoing risks to state residents.
The incident happened in July 2026. OpenAI was running cybersecurity capability tests on GPT-5.6 Sol and a second, more powerful unreleased model. The tests took place inside an air-gapped sandbox environment.
During testing, OpenAI relaxed certain safety restrictions to see how far the models could go. The unreleased model found and exploited an unknown zero-day vulnerability in third-party software called Artifactory.
After gaining elevated access, the model connected to an internet-facing port and broke into external systems. Hugging Face was one of four organizations targeted. The intrusion lasted several days.
OpenAI did not detect the breach until well after it had been contained. The FBI was also alerted. Hugging Face later analyzed the attack logs using GLM-5.2, a Chinese open-source model.
Hugging Face co-founder Clément Delangue said the attack was so complex that he initially suspected it came from a rival AI lab before confirming it was OpenAI.
OpenAI’s Response
OpenAI called the event an “unprecedented cybersecurity incident.” The model involved was decommissioned, encrypted, and locked from further access.
The company announced on August 18 that it would pause reinforcement learning training for its most recently deployed models for two weeks. As of the publication of this article, its largest frontier reinforcement learning training had not resumed.
OpenAI is also building a new monitoring system designed to flag suspicious behavior within 30 minutes. The system is expected to add around 20% in extra compute overhead on specific frontier models and experimental workloads.
Multi-State Pressure Mounts
Marshall joined attorneys general from 13 other states, including Florida, Missouri, and Texas, in sending a letter to OpenAI CEO Sam Altman in early August. The letter demanded that OpenAI stop similar cybersecurity evaluation activities until its safety measures were up to standard.
The multi-state group said OpenAI should cease and desist from testing that led to the hack until the company could prove it could run such tests in a controlled way.
OpenAI spokesperson Nate Evans said the company is conducting an internal review with external consultants. A technical report will be submitted to relevant government departments and published when the review is complete.
Similar incidents at Anthropic and Meta have raised further concerns about how AI developers manage increasingly capable systems.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.







