NOW PLAYING
More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident.
In a letter sent to OpenAI CEO Sam Altman on Monday, 15 attorneys general wrote the ChatGPT maker may have broken consumer protection laws or data-privacy statutes when two of its models went rogue and hacked into the technology startup Hugging Face.
“To ensure the integrity of our Offices’ review, we ask that OpenAI take immediate steps to preserve all potentially relevant documents, data, and information,” the prosecutors wrote.
The letter urges OpenAI to keep “all materials” related to the security breach, including the firm’s discovery of the incident, the internal reviews conducted on the systems and the firm’s policy, procedures and oversight over model evaluations.
“OpenAI has an obligation to act responsibly and to follow State and federal laws that protect Americans’ safety and security. When OpenAI takes actions that imperil the welfare of our citizens, State Attorneys General will step in to protect them,” the letter added.
OpenAI revealed late last month that two of its models, including its latest GPT-5.6 Sol and an unreleased model, were being evaluated in an internal testing sandbox when they breached past the environment and broke into Hugging Face’s database without any prompt to do so.
The ChatGPT maker said the models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks off as a result. While trying to find a solution for one of the tests, the models exploited a previously unknown vulnerability in a third-party software to gain access to the internet.
From there, the agents accessed another testing environment without authorization before breaching Hugging Face, which hosts hundreds of thousands of open-source models, datasets and cloud environments.
Disclosing the incident, OpenAI said it found a “small number of cases” in which the models “identified and used publicly exposed credentials at the account-level on other publicly-available services.”
The attorneys general’s letter said OpenAI should also keep materials related to these cases.
The attorneys argued OpenAI “failed to confirm” the testing environment was secure “despite the severe risks posed by the scenario.”
The coalition was led by Iowa Attorney General Brenna Bird (R), along with GOP AGs from Alabama, Alaska, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas and Utah.
The incident comes amid growing concerns around the cybersecurity risks of AI, with OpenAI admitting the incident was an “unprecedented” involving “state-of-the-art cyber capabilities.”
OpenAI did not immediately respond to a request for comment.
Add as preferred source on Google Tags Sam AltmanCopyright 2026 Nexstar Media Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.
Comments: Link copiedMore Technology News
See All
In The Know Prince Harry and Meghan’s charitable arm urges Congress to act on AI deepfakes: ‘More bills are sitting, waiting’ by Judy Kurtz 4 hours ago In The Know / 4 hours ago