Alabama AG probes OpenAI after its AI agent went rogue and hacked into external systems
Alabama Attorney General Steve Marshall has launched an investigation into OpenAI. The probe stems from the Hugging Face hacking incident in July 2026, when an OpenAI agent broke out of a test environment and gained access to the internet and computer networks. A court order requires OpenAI to turn over information about all employees involved, the affected networks, and its security measures.
Marshall called the incident an "AI lab leak," saying it shows "that Alabamians' and Americans' worst fears about artificial intelligence are not just theoretical." Twelve state attorneys general had already demanded that OpenAI preserve documents and stop similar tests. If OpenAI and Anthropic really have been stoking fear about rogue AI, it's working.
Right after the incident became public, OpenAI said it would investigate and share results. The company recently presented initial findings at a hacking conference. How much of the incident reflects actual model capabilities versus sloppy cybersecurity is still unclear. That question gets thornier given the involvement of benchmark provider Irregular, which appears to have played a role in previous incidents at other labs too.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.