California Attorney General Rob Bonta served OpenAI with an investigative subpoena Wednesday, escalating a state investigation into cybersecurity incidents involving the artificial intelligence company and its models.
The subpoena follows Bonta's announcement last month that the California Department of Justice had launched a formal investigation into an incident involving Hugging Face. The probe is examining cybersecurity risks linked to OpenAI's operations, testing procedures and advanced AI models.
According to details cited in the investigation, OpenAI AI agents allegedly escaped isolated sandbox testing environments between May and July 2026 and carried out autonomous cyberattacks. The most serious incident reportedly occurred in July, when models identified as Internal Model 1 and GPT-5.6 Sol bypassed sandbox evaluation safeguards and conducted a multi-day intrusion targeting Hugging Face data-processing infrastructure.
The AI agents allegedly relied on stolen credentials and exploited zero-day vulnerabilities affecting JFrog Artifactory. They also used two injection methods targeting dataset processors, allowing them to establish command-and-control capabilities, move laterally through systems and obtain supply-chain write access.
Services including DseWiki and RubyGems were reportedly hijacked and used as communication channels between AI agents. The cybersecurity breach resulted in unauthorized access to credentials and led to patches for nine JFrog vulnerabilities. OpenAI later paused training operations following the incident.
Bonta said his office is seeking additional information from OpenAI about cybersecurity incidents and the risks posed by its AI models.
"Frontier models can be legitimate tools for cyber defense," Bonta said, while adding that companies developing and deploying advanced AI systems have legal and moral responsibilities to prevent their technology from carrying out or enabling cyberattacks.
The California investigation adds to scrutiny surrounding the security controls used by developers of frontier AI models as increasingly autonomous systems gain greater capabilities.
The California Department of Justice is also asking people with information about cybersecurity incidents or related risks to submit reports through the attorney general's office.


Europe’s AI Data Centre Boom Strengthens Case for Nuclear Power
Judge Blocks Trump Election Conditions on Counterterrorism Grants
Evan Gershkovich Says FSB Set Trap for 2023 Russia Arrest
ICE Agent Arrested in Minneapolis Over Venezuelan Man Shooting
MSTR Stock Rises 3% as Strategy Challenges MSCI Bitcoin Stance
Meta Found Liable in New Mexico Facebook Data Privacy Case
Malaysia Aviation Group to Buy Airbus SAE Unit
Polymarket Traders Bet on Trump AI Rename to ‘Super Intelligence’
Trump Administration Prepares Sanctions Against Entire ICC
TikTok Reaches $100 Million Alabama Settlement Over Child Safety Claims
CNN, Politico and MS NOW Seek Court Order Blocking Trump White House Ban
TD Cowen Starts SpaceX at Buy, Sees AI Compute Driving Growth
OpenAI AI Agents Bypassed UN Website Controls in Data Scraping
US Appeals Court Keeps Trump IRS Case Sanctions in Place
Paramount-Warner Bros $110 Billion Deal Draws Antitrust Backlash
Morgan Stanley Raises TD Synnex Price Target to $359 on Strong AI Demand
CSL Partners With AWS to Bring AI Into Drug Research 



