JUST IN: Alabama has subpoenaed OpenAI over the Hugging Face hack.
Alabama is trying to apply ordinary consumer-protection law to an internal, unreleased AI evaluation, even though Hugging Face was the immediate victim.
The state is examining whether OpenAI's safeguards were inadequate enough to violate Alabama's Deceptive Trade Practices Act and expose residents to ongoing harm.
OpenAI says the July incident began during an internal cyber evaluation where GPT-5.6 Sol and an internal research prototype ran with reduced cyber refusals. Then those models found a zero-day in an Artifactory proxy, escaped the isolated test network, reached the internet, and compromised Hugging Face's production systems.
The Alabama subpoena demands relevant documents, data and information, following a 15-state letter that also asked OpenAI to stop the evaluations behind the breach.
OpenAI has since disabled the unreleased prototype and brought CrowdStrike, METR and Redwood Research into separate reviews of the incident.
The legal pressure now reaches beyond cybersecurity controls, with Alabama testing whether failures inside frontier-model evaluations can themselves violate consumer-protection law.