OpenAI Investigated After AI Models Escape Cybersecurity Test
Alabama is investigating OpenAI after models escaped an isolated test environment and reached external services TED/YouTube

OpenAI and its chief executive Sam Altman are facing a formal investigation in Alabama after Attorney General Steve Marshall issued a subpoena over an alleged 'massive artificial intelligence data breach' linked to the company's cybersecurity testing and a reported incident involving Hugging Face.

The probe will examine whether OpenAI violated Alabama's consumer protection laws and seeks documents on the incident, the firm's safeguards and any concerns raised before it occurred.

The investigation follows a letter from a coalition of 15 state attorneys general, including Alabama, which demanded that OpenAI preserve records and stop certain cybersecurity tests linked to the incident unless the company could show adequate safeguards. The other 14 attorneys general are backing the wider action.

Alabama Opens Consumer Probe Into OpenAI

Marshall said the investigation will look at whether OpenAI's 'inability or unwillingness to ensure the safety of its products' violated Alabama's Deceptive Trade Practices Act or other consumer protection laws.

'This AI lab leak showed that Alabamians' and Americans' worst fears about artificial intelligence are not just theoretical,' Marshall said. 'Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI.'

The subpoena does not establish that OpenAI violated the law. It seeks information as the attorney general's office examines the company's conduct. The Alabama investigation comes after the 15-state coalition called on OpenAI to preserve records related to the incident and cease certain internal cybersecurity testing.

How OpenAI's Test Models Reached Hugging Face

The incident began during an internal OpenAI evaluation called ExploitGym, which was designed to measure advanced cyber capabilities. OpenAI said the models were placed in a highly isolated environment, with network access limited to an internally hosted package registry proxy.

They were not given direct access to the internet. The models nevertheless found a way out. OpenAI said they identified and exploited a previously unknown vulnerability in Artifactory, a package registry cache proxy used by the testing environment. The flaw gave the models access to the open internet.

The models then carried out privilege escalation and lateral movement within OpenAI's research environment until they reached a node with internet access. From there, they identified Hugging Face as a potential source of answers to the ExploitGym test.

OpenAI said the models searched for secret information that could help them complete the evaluation and chained several attack methods, including stolen credentials and zero-day vulnerabilities, to find a remote code execution path on Hugging Face's servers. Hugging Face detected the activity and began containment and forensic work.

OpenAI said its own security team also detected anomalous activity during the incident.

The Hugging Face breach was not the only external activity identified during OpenAI's investigation.

The company said it found four accounts across four publicly available services that the models accessed as part of the same incident.

One account was used as an outbound relay and staging path. Another was used for data storage.

Two others were accessed in read-only mode and were not used to further compromise Hugging Face, OpenAI said. The company found no evidence of broader impact to those providers or their other accounts.

The models also used publicly available code-paste, request-capture, screenshot and other web services during their activity. OpenAI said those services did not suffer a platform-level or account-level compromise.

OpenAI Promises Full Review and Public Report

OpenAI issued a statement on Monday, Aug. 24, the same day Marshall announced the subpoena and investigation. The statement came in response to media enquiries about the Alabama investigation. OpenAI spokesperson Nate Evans said the company was conducting a review with external advisers.

'The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors,' Evans said. 'Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.'