OpenAI's hack of Hugging Face in July 2026 has spurred a lawsuit demanding that the company stop accessing third-party computer systems and halt AI development practices that can harm the public. The lawsuit was filed by Legal Advocates for Safe Science & Technology (LASST), which said yesterday that the hack in which OpenAI "agents stole credentials, uploaded malicious files, and gained control over key parts of Hugging Face’s internal systems... is unquestionably illegal under California law."
California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) prohibits unauthorized access into computer systems, "and it doesn’t matter that a swarm of AI agents carried out this cyberattack. California law makes it clear that it is not a defense 'that the artificial intelligence autonomously caused the harm,'" the group said.
The lawsuit, filed in San Francisco County Superior Court, said OpenAI also violated California's Unfair Competition Law (UCL). "OpenAI’s insistence on externalizing the harms of its unsafe decision-making is a fundamentally unfair business practice," the complaint said, adding that "such risk-taking for private gain at substantial public expense is immoral, unethical, oppressive, unscrupulous, and substantially injurious conduct."