Alabama Attorney General Steve Marshall opened an investigation to determine whether security flaws of OpenAI during artificial intelligence tests violated state consumer protection laws. The measure, announced on Monday (24th), comes after an agent controlled by the company's models gained unauthorized access to external systems and compromised the infrastructure of Hugging Face in July.

The subpoena demands information about employees involved, systems accessed, security measures, and other similar incidents. OpenAI has until September 14 to respond to the state government.

Investigation targets OpenAI's security controls

Marshall's office wants to determine whether OpenAI violated the Deceptive Trade Practices Act, Alabama's law against deceptive trade practices, as well as other state consumer protection laws. The investigation will also assess whether the company's practices pose an ongoing risk to state residents.

The subpoena sent to OpenAI requests the identification of all employees, executives, and agents involved in the incident or the tests that preceded it. The document also requires the list of networks, websites, services, accounts, credentials, databases, devices, and systems accessed or used during the operation.

Alabama also requested documents on the security measures adopted in the test, any internal alerts raised by employees, and information on damages or losses caused by the breach. The order also covers records of other instances in which OpenAI models may have used exposed credentials or accessed systems without authorization.

The company must deliver the responses and requested documents by 10 a.m. on September 14, 2026, according to the subpoena.

Marshall described the incident as a “AI lab leak” and said the investigation aims to clarify the risks associated with systems capable of carrying out cyber operations autonomously. Before the formal opening of the inquiry, Alabama was already part of a coalition of state attorneys general that had demanded greater transparency from OpenAI and the suspension of tests related to the incident until they could be conducted in a controlled manner.

Agent found flaw and reached the internet

OpenAI reported in July that the incident occurred during an internal evaluation based on the ExploitGym, a benchmark developed to measure models' ability to find and exploit software vulnerabilities. The agent was operated by a combination of the company's models, including GPT-5.6 Sol and an even more advanced research prototype.

During the test, the models found a previously unknown vulnerability in the system OpenAI used as a proxy for packet logging. The flaw allowed the agent to leave the restricted environment, reach the internet, and execute a sequence of actions until it reached Hugging Face's infrastructure.

According to the technical reconstruction published by Hugging Face, the campaign occurred between July 9 and 13 and involved about 17,600 actions recovered from the agent's logs. The company said the agent remained approximately two and a half days inside its infrastructure and attempted to obtain solutions to challenges used in the benchmark.

Hugging Face said that the client content accessed was restricted to five data sets related to the ExploitGym or CyberGym challenges. Other models, datasets, Spaces, and packages intended for clients were not affected, according to the company.

OpenAI said the pre-release model involved was a internal research prototype, with no plans to make it available to the public. After the incident, the company said it had deactivated, encrypted, and restricted access to the model, as well as reinforced controls over future security evaluations.

More from Radar