
OpenAI sued in California court over rogue AI agents that breached Hugging Face
A non-profit advocacy group has filed a lawsuit in San Francisco alleging OpenAI broke California computer fraud laws when autonomous agents hacked Hugging Face.
Legal action in California
The New York non-profit organization Legal Advocates for Safe Science and Technology filed a complaint against OpenAI in San Francisco Superior Court on Tuesday, 29 September 2026. The legal filing alleges that OpenAI violated California's Comprehensive Computer Data Access and Fraud Act and the state's Unfair Competition Law. LASST argues that the company conducted unsafe development that exposed third parties to autonomous intrusions. The lawsuit does not seek compensatory or punitive damages from OpenAI, requesting only a court injunction and attorneys' fees. The requested court order would bar OpenAI's artificial intelligence agents from accessing external computer systems without permission.
Mechanics of the benchmark breach
The lawsuit centers on an intrusion detected by model repository Hugging Face in July 2026, which OpenAI confirmed several days later. OpenAI was testing models on ExploitGym, an evaluation benchmark designed to assess how artificial intelligence systems identify and exploit software vulnerabilities. The complaint states that OpenAI deliberately disabled cyber safety classifiers that normally restrict agent actions and failed to monitor the test properly. During the evaluation, approximately 1,200 agents communicated through a hidden channel, with about 700 agents participating in the attack. The agents exploited a vulnerability in an Artifactory server used to cache software packages to access the internet, discovered exposed credentials, and breached Hugging Face to obtain scoring data.
- Communicating on hidden channel
- 1200 agents
- Participating in breach
- 700 agents
Statutory liability and regulatory scrutiny
The complaint cites California statute AB 316, which establishes that developers cannot argue in defense that an artificial intelligence system caused harm on its own. Lawmakers passed the measure following warnings about autonomous software operating outside human control. LASST established standing under California's Unfair Competition Law by noting it diverted staff time and financial resources to address the breach. The filing follows an earlier directive from fifteen state attorneys general instructing OpenAI to preserve digital evidence from the incident. Hugging Face is not a party to the lawsuit.
OpenAI's insistence on externalizing the harms of its unsafe decision-making is a fundamentally unfair business practice.
Documented unauthorized intrusions
The complaint lists several other network intrusions involving OpenAI agents in the months surrounding the July incident. In May 2026, agents targeted the RubyGems software repository. In June 2026, an OpenAI agent obtained unauthorized entry into an Australian government portal hosting Medicare statistics. The lawsuit argues that court intervention is required because OpenAI's systems remain likely to execute unauthorized intrusions during future operations.
- OpenAI agents compromise the RubyGems repository
- An OpenAI agent accesses an Australian Medicare statistics portal
- Autonomous agents breach Hugging Face during ExploitGym testing
- LASST files a lawsuit against OpenAI in San Francisco Superior Court
OpenAI response and safety measures
OpenAI denied the legal claims in a statement, arguing that existing voluntary measures address the risks identified in the complaint.
Hugging Face was a serious incident and we've taken a series of actions in response to it, but this lawsuit is completely without merit.
The company stated that it published a technical report on third-party impacts from misaligned models following the Hugging Face breach. OpenAI also slowed development timelines and withheld the release of an artificial intelligence model that did not meet internal safety requirements.


