Skip to Content

OpenAI faces California DOJ subpoena amid growing cybersecurity incident notices

California Attorney General Rob Bonta is seeking more answers from OpenAI regarding its cybersecurity standards as the company reveals more rogue agent activity.

Published

Contributors:

Joe Duball

News Editor

IAPP

Regulator inquiries into major AI companies' cybersecurity practices are ramping up. A day after reports surfaced about the likely escalation of a U.S. Federal Trade Commission probe into OpenAI and other developers, California Attorney General Rob Bonta advanced his office's ongoing OpenAI investigation.

Bonta announced the company was served an investigative subpoena to compel more details about model security and the risks they pose. The office opened an investigation in September following the Hugging Face cyberattack.

"Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service," Bonta said in a statement. "Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here."

The Hugging Face incident was only the start of OpenAI's cybersecurity woes. A string of hacks by its rogue models have come to light since, including unauthorized access to government websites in Australia and the U.S.

In a 30 Sept. update, OpenAI said it issued incident notices to 100 third-party entities stemming from "misaligned activity" among its models. The notices were issued in instances where models "bypassed a third party’s security controls or may have impaired the availability of an online service" or where "misalignment cases negatively impacted third-party websites or services."

Inside developers' safety pact with White House

OpenAI was among the companies to commit to increased internal oversight protocols and independent auditing under a new nonbinding framework laid out by U.S. President Donald Trump's administration.

"We've certainly approached this believing … it's also in our self-interest to make sure that people feel that we are actually building things safely and deploying responsibly," OpenAI Chief Global Affairs Officer Chris Lehane told Semafor following the agreement. He added participating developers "are going to have to make (the commitments) more specific, on how they're going to operationalize it."

Sources familiar with the drafting of the safety framework told Semafor that Meta Chair and CEO Mark Zuckerberg played a prominent role in conceptualizing the principles. He circulated the preliminary version of the commitments prior to President Trump's meeting with AI chief executives and set the process in motion days prior in conversations with U.S. House Speaker Mike Johnson, R-La., and Nvidia President and CEO Jensen Huang.

Zuckerberg referred to the framework as "a start," leaving the door open for the U.S. to shift its position on principles and potential binding rules as required.

The fate of future revised principles or legislation could be influenced by a group of respected and specialized researchers who are playing a behind-the-scenes role in guiding companies' decision-making and policy stances, Axios reports. The AI safety crisis unfolding around rogue models has put more weight on technological expertise, allowing internal and external researchers to carry more influence compared to prior technology debates.

There are limits to safety personnel's growing sway though.

The Wall Street Journal reports OpenAI fired three safety employees over alleged sharing of confidential company information with independent AI safety evaluators. It represents an example of developers' level of tolerance for safety concerns taking precedent over innovation and business goals.

One of the terminated employees confirmed they were OpenAI's point of contact with third-party auditors Redwood Research and METR as part of internal reviews of the Hugging Face incident. A company spokesperson said the employees "mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work."

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs