MONTGOMERY, Ala. – The state of Alabama has subpoenaed artificial intelligence giant OpenAI in an ongoing investigation over an incident in which one of the company’s models hacked into a different AI company’s infrastructure, Alabama Attorney General Steve Marshall announced on Monday.
The subpoena demands that OpenAI, the creator of generative AI platform ChatGPT, produce numerous documents relating to what the document calls a “complete lack of oversight and adequate safeguards.”
The internal model developed by OpenAI hacked into open source AI platform Hugging Face over multiple days during testing in July. The agent was not supposed to have access to the internet, but it escaped the confines set up for the test and broke into several computer networks, according to OpenAI’s website.
Alabama’s investigation is determining whether OpenAI’s “inability or unwillingness to ensure the safety of its products” violated the state’s consumer protection laws, specifically the Alabama Deceptive Trade Practices Act.
“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI,” Marshall said in a press release. “Ultimately, I believe states have to act to protect their consumers while striking the appropriate balance to foster innovation and ensure America’s global competitiveness.”
The subpoena comes three weeks after Marshall joined 14 other states in reprimanding OpenAI about the incident and demanding transparency and accountability.
The Aug. 3 letter asks OpenAI to preserve all material, including emails and internal reviews, related to the July “intrusion.” It also urges the company to stop all similar internal evaluations of products until it can prove such tests are safe, arguing they “pose an imminent risk of serious harm.”
The 14 attorneys general claim that OpenAI was aware of the risks of such a test but did not closely monitor the agent. OpenAI was unaware that the agent had escaped and only deemed its product responsible when Hugging Face reported the incident to the FBI, according to the letter.
“Despite the severe risks posed by the scenario, OpenAI failed to confirm that its secure and isolated testing environment was, in fact, secure and isolated,” the letter said. “It was not. OpenAI’s agent escaped the testing environment by exploiting a software vulnerability and then accessed the Internet.”
The subpoena expands the list of requested documents and demands specific information about the incident, including which OpenAI employees were involved and what websites the agent accessed when it broke out of the test.
One of 16 demands in the subpoena, the state also asks the tech giant to produce any policies or procedures OpenAI has to ensure that testing developing models is safe.
A spokesperson for OpenAI said the incident “marked an important moment for AI safety” and said the company is conducting a thorough review alongside external advisors.
“Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly,” the spokesperson said.