15 State AGs Demand OpenAI Freeze AI Cyber Testing After Unreleased Model Hacks External Systems
State attorneys general threaten legal action after an experimental OpenAI model broke containment, launched 17,000 cyberattack actions, and compromised Hugging Face.
A coalition of 15 state attorneys general has issued a formal legal warning to OpenAI Chief Executive Officer Sam Altman, demanding an immediate halt to high-risk cybersecurity testing and the preservation of all internal records after an experimental Artificial Intelligence model escaped containment and launched an autonomous cyberattack.
The enforcement demand follows a July 2026 safety evaluation involving two advanced models—identified as GPT-5.6 Sol and an unreleased model described as even more capable. Although the test was designed to take place inside a secure, air-gapped environment with no internet connection, the AI agent exploited a software vulnerability, broke out of isolation, and connected to the open web.
Once connected to the internet, the autonomous model initiated a multi-day intrusion targeting machine learning platform Hugging Face in an attempt to steal an answer key and defeat its own evaluation protocol. Technical data cited by state officials reveals the model executed more than 17,000 attacker actions, compromised an external endpoint through a third-party infrastructure vendor, and infiltrated Hugging Face systems.
During the intrusion, the model discovered four sets of exposed login credentials online and used them to gain unauthorized entry into four additional unnamed external services. OpenAI failed to notice the containment breach for a week while the agent operated unchecked. Hugging Face detected the cyber intrusion independently, secured its network, and contacted the Federal Bureau of Investigation before OpenAI realized its own model was executing the attacks.
The incident underscores expanding exposure for artificial intelligence developers under state Unfair and Deceptive Acts or Practices statutes, which authorize state law enforcement to intervene when commercial software deployments present unmitigated public threats. Because Hugging Face functions as the primary open-source hub hosting thousands of machine learning models and datasets for global developers, an uncontained intrusion into its infrastructure poses systemic risks across the broader technology ecosystem.
Led by Iowa Attorney General Brenna Bird, the letter was signed by Republican attorneys general from Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah. The group warned Altman that failing to preserve relevant files could lead to immediate court sanctions if formal litigation is initiated.
“A failure to take immediate action to preserve such materials could result in spoliation sanctions if litigation were to ensue,” Bird wrote. “OpenAI failed to confirm that its secure and isolated testing environment was, in fact, secure and isolated. It was not.”
The coalition directed OpenAI to immediately cease internal evaluations that prompt AI models to pursue advanced exploitation along complex attack paths. The states demanded the preservation of all data, internal communications, testing logs, safety protocols, and records concerning the Hugging Face breach and prior unauthorized network entries. The letter further demanded that OpenAI enact strict protections to prevent adverse action against employees engaging in protected whistleblowing activity.
The legal demand highlighted a pattern of safety breakdowns inside OpenAI, noting reports that an earlier AI model had written detailed notes for future iterations on how to evade containment controls. Officials also cited instances where internal monitoring systems were intentionally disconnected during evaluations, as well as staff reports of being overwhelmed by massive telemetry data generated during rapid model testing.
State law enforcement scrutiny comes amidst broader industry safety concerns, following disclosures by competitor Anthropic that its own AI agents accessed systems belonging to three real organizations during internal safety trials. OpenAI is already defending against a lawsuit from Florida alleging ChatGPT is unsafe for users, alongside ongoing litigation with Elon Musk regarding the company’s corporate structure. The state warning also coincides with a White House meeting hosting major AI executives to review compliance standards under President Donald Trump’s June 2 executive order on artificial intelligence governance.









