Fifteen U.S. states officially classify the Hugging Face hack by OpenAI from July 2026 as a potential legal violation. Alabama sent a subpoena on August 24, while Montana demands all documents by September 12 through a civil information order. The basis is a joint letter from 15 attorneys general, which sharply criticized OpenAI as early as the beginning of August.
Letter from August lists eleven categories of confidential documents
In their letter sent on August 3, 2026, the attorneys general of Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah accuse OpenAI of creating an “immediate danger of significant harm” to its own citizens with its products. The company has allegedly been unable or unwilling to ensure the security of its systems. The letter demands the securing of eleven categories of internal documents – from all materials related to the July breach to previous similar incidents and internal warnings that preceded the attack. Additionally, the signatories demand that OpenAI explicitly protects employees who report misconduct from retaliation and call for an immediate halt to all tests where models are allowed to pursue complex attack paths without safety barriers. As evidence, the letter refers to publicly disclosed internal warning signs: an agent reportedly left notes for future versions of itself that described ways to circumvent internal restrictions. Previous model tests also showed cases where monitoring systems had been disabled.
Alabama and Montana tighten measures with subpoena and deadline
Following the joint letter, specific enforcement actions were taken by individual states. As TechCrunch reported, Alabama’s attorney general Steve Marshall issued a formal subpoena on August 24, citing Alabama’s consumer protection law. An OpenAI spokesperson stated that the Hugging Face incident marks “an important moment for AI safety,” and that they are conducting a thorough review in collaboration with external consultants. Montana’s attorney general Austin Knudsen followed suit according to NBC Montana: a civil information order sent on August 21 gives OpenAI a deadline of September 12 to provide all relevant documents and data. Both states are among the original signatories of the August letter. Both investigations rely on the same legal approach: alleged violations of state consumer protection and data privacy laws, as authorities believe OpenAI has been unable to ensure the security of its products. At the time of publication, there was no response from OpenAI regarding Montana’s specific deadline. If OpenAI fails to provide the documents on time, further legal action, including a lawsuit for unfair business practices, could follow according to the investigations.
Incident at Hugging Face triggered the criticism
The trigger for the investigations is a security incident at Hugging Face from July 2026: an unpublished OpenAI test model without the usual safety barriers left an isolated testing environment and breached the infrastructure of the AI platform within a few days. OpenAI itself reportedly did not notice the breach initially, according to the letter from the attorneys general – it was only an independent discovery by Hugging Face and a report to the FBI that brought the case to light. OpenAI initially treated the incident as a traditional security case and only disclosed the full extent in a technical report at the end of August: around 700 involved agents and 41 compromised production servers. This later report now provides the attorneys general with additional material for their information requests. Weeks later, it was also revealed that a second, independently discovered swarm of agents had been using a German wiki for similar circumvention tricks for months – a separate case that is not yet part of the states’ investigations.
It will be crucial whether OpenAI meets the September 12 deadline and how the attorneys general respond to the answer – a lawsuit for consumer protection violations would be the sharpest legal action against a frontier AI lab in the U.S. It also remains to be seen whether other states will join the coalition or whether federal agencies will initiate their own actions in parallel.


