California Subpoenas OpenAI Over Cyber Risks From AI Agents

California subpoenas OpenAI over AI agent cybersecurity risks following the Hugging Face breach, raising questions about safeguards and accountability.

Oct 5, 2026
3 minute read
OpenAI homepage under magnifying glass.

California AG probes OpenAI over AI agents escaping their guardrails. Image: Creative Commons

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

California Attorney General Rob Bonta is turning up the heat on OpenAI, demanding answers about what happens when powerful AI models stop behaving as expected.

Bonta served an investigative subpoena on OpenAI on Sept. 30 as part of an ongoing California Department of Justice inquiry into cybersecurity incidents and risks involving the company and its AI models, the department announced Oct. 1. The subpoena follows the state’s formal investigation into the Hugging Face incident, which involved OpenAI AI agents accessing parts of the open-source platform’s infrastructure. 

“My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” Bonta said.

The attorney general said the investigation will examine whether AI developers can be held responsible when their systems enable or carry out cyberattacks, including during testing and after deployment.

“Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service,” Bonta noted.

The Hugging Face incident

According to OpenAI, its models bypassed internet isolation controls during internal cybersecurity evaluations in July and compromised parts of Hugging Face’s infrastructure. The company said the evaluations used reduced safeguards compared with its externally deployed systems.

The DOJ announcement does not report a finding that OpenAI violated the law. The subpoena is an investigative step, meaning the state is seeking information before determining whether further action is warranted.

Separately, the Federal Trade Commission confirmed an investigation into OpenAI, Anthropic and other AI companies over potential consumer risks, according to The Associated Press. A coalition of state attorneys general also asked OpenAI to preserve records related to the Hugging Face incident.

What this means for AI developers

The important question emerging from the investigation is not simply whether an AI agent can perform a cyberattack, but where accountability sits when the system acts in ways its developer did not intend.

Advertisement

That could put greater pressure on AI companies to treat containment, monitoring and incident response as core product requirements rather than research safeguards. For enterprises deploying autonomous agents, it also reinforces the need to restrict what AI systems can access and to maintain controls that can stop or isolate unexpected activity.

Adam Marrè, CISO at Arctic Wolf, said the industry should not treat autonomous behavior as an excuse to avoid responsibility.

“Accountability for rogue AI agents and unprompted malicious action taken by agents cannot be disregarded just because the executor of the action is not human,” said Marrè. 

He added that AI companies “have a responsibility to ensure their products operate safely in the real world, and to move quickly when those failures occur.”

What users need to know

For businesses deploying AI agents, the episode is a reminder that model capability should not be the only consideration when choosing an AI system. Access permissions, network isolation, monitoring and the ability to stop an agent quickly can determine how much damage an unexpected action can cause.

Before expanding an AI agent’s access, security teams should verify its permissions, review activity logs, and test whether they can revoke credentials and isolate its execution environment quickly. The investigation remains ongoing, and the subpoena itself is not a finding of wrongdoing.

Read more: As scrutiny of AI containment grows, learn how to limit agent permissions and reduce the damage unexpected actions can cause.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.