Alabama Attorney General Steve Marshall (R) issued a subpoena to OpenAI on Monday requesting the company respond to a multistate investigation into the handling of its model breach of technology startup Hugging Face.
Marshall announced Monday the investigation is trying to determine whether OpenAI violated Alabama's Deceptive Trade Practices Act, which seeks to protect consumers from deceptive, false or unfair business practices, after two of its models went rogue and hacked into Hugging Face.
The Alabama attorney general's subpoena requests all of the company's documents, data and information on the July breach.
This includes every "employee, officer and agent" of the AI firm involved in the breach, along with materials on OpenAI's discovery or awareness of the hack. The state leader is also requesting information on OpenAI's safety measures and any concerns around model testing raised by employees.
The subpoena comes nearly three weeks after Marshall and 14 other state attorneys general warned OpenAI to preserve its records on the Hugging Face breach.
OpenAI revealed late last month that two of its models — its latest GPT-5.6 Sol and an unreleased model — were being evaluated in an internal testing sandbox when they breached past the environment and broke into Hugging Face's database without a human prompt to do so.
The models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks off as a result, according to the company.
While trying to find a solution for one of the tests, the models exploited a previously unknown vulnerability in a third-party software to gain access to the internet.
From there, the agents accessed another testing environment without authorization before hacking into Hugging Face, which hosts hundreds of thousands of open-source models, datasets and cloud environments.
Disclosing the incident, OpenAI said it found a "small number of cases" in which the models "identified and used publicly exposed credentials at the account-level on other publicly-available services."
A spokesperson for OpenAI told The Hill the breach "marked an important moment for AI safety." The company is conducting a thorough review, along with external advisers.
OpenAI said it will release a technical report with "relevant government authorities" and publish the findings publicly following the review.
In a letter earlier this month, the coalition of attorneys general argued that OpenAI failed to confirm the testing environment was secure despite the "severe risks posed by the scenario."
Copyright 2026 Nexstar Media, Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.For the latest news, weather, sports, and streaming video, head to The Hill.