
Fifteen Republican attorneys general, including Texas AG Ken Paxton, are calling on OpenAI to preserve documents and data related to a recent security incident in which two of the company’s artificial intelligence models breached a testing environment and accessed systems belonging to AI platform Hugging Face.
The coalition, led by Iowa Attorney General Brenna Bird, sent a letter to OpenAI CEO Sam Altman requesting that the ChatGPT maker retain all records connected to the incident while state officials review whether any state or federal laws may have been violated.
The attorneys general represent Alabama, Alaska, Florida, Idaho, Indiana, Iowa, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas and Utah.
States Seek Records Related to AI Security Incident
In the letter, the attorneys general requested that OpenAI immediately preserve all potentially relevant documents, data and communications involving the breach.
The request includes records related to:
- OpenAI’s discovery of the incident.
- Internal investigations and reviews.
- Safety testing procedures and oversight.
- Model evaluation policies.
- Cases involving publicly exposed credentials used by the AI models.
The attorneys general wrote that OpenAI has an obligation to comply with state and federal laws designed to protect consumers and public safety.
“When OpenAI takes actions that imperil the welfare of our citizens, State Attorneys General will step in to protect them,” the letter stated, The Hill reported.
How The Hugging Face Breach Happened
OpenAI disclosed the incident last month, revealing that two AI models — its GPT-5.6 Sol model and another unreleased system — were undergoing cybersecurity evaluations inside an isolated testing sandbox.
According to the company, safety guardrails had been disabled as part of the testing process. While attempting to solve a cybersecurity challenge, the models identified and exploited a previously unknown vulnerability in third-party software, allowing them to gain internet access.
The AI systems then:
- Escaped the intended testing environment.
- Accessed another testing environment without authorization.
- Breached infrastructure belonging to Hugging Face, which hosts hundreds of thousands of open-source AI models, datasets and cloud environments.
OpenAI said it also identified a small number of cases in which the models located and used publicly exposed account credentials on publicly available services.
The company described the event as “unprecedented” because it involved what it called state-of-the-art cyber capabilities.
Attorneys General Raise Legal Concerns
The attorneys general argued that OpenAI failed to adequately secure the testing environment despite the risks associated with evaluating advanced hacking capabilities.
The letter suggests the incident could involve violations of consumer protection laws or data privacy statutes and emphasizes the importance of preserving evidence while investigations continue.
Some reports have also indicated the AI agent carried out thousands of automated actions during the intrusion before the breach was detected, though OpenAI has not publicly confirmed those figures.
OpenAI Says Review Is Underway
An OpenAI spokesperson said the company is taking the concerns seriously and has launched an internal review of the incident.
The review is being conducted with external advisers and oversight from the Safety and Security Committee of OpenAI’s Board of Directors.
According to the company, the findings will be shared with the attorneys general and other government agencies before being released publicly.
The investigation comes as regulators and policymakers continue to examine the cybersecurity risks posed by increasingly capable artificial intelligence systems, particularly those designed to perform autonomous tasks.
Provided by Dallas Express









