OpenAI just got slapped with a lawsuit over the incident this summer in which its AI agents went rogue during internal testing and hacked Hugging Face, a major repository for AI models and datasets. The breach has since helped spark a broader debate over the risks of AI systems becoming harder to control.
The nonprofit Legal Advocates for Safe Science and Technology (LASST) filed the lawsuit Tuesday in San Francisco Superior Court, alleging that the breach violated California’s anti-hacking law. LASST v. OpenAI appears to be the first lawsuit filed specifically over the Hugging Face hack, though the incident had already been invoked in other litigation against OpenAI.
LASST says it has standing to sue under California’s Unfair Competition Law because it had to divert staff time and resources to respond to the incident. The group also argues that “OpenAI’s insistence on externalizing the harms of its unsafe decision-making is a fundamentally unfair business practice.”
According to the lawsuit, OpenAI deliberately disabled cyber safety classifiers that would normally constrain its agents and failed to adequately monitor them during testing.
“We are filing this suit because OpenAI violated the law—and it needs to be held accountable. OpenAI and frontier AI developers more broadly can’t avoid the consequences of their unsafe actions just by claiming that ‘an AI did it,’” the group also wrote in a blog post.
The lawsuit comes a few months after Hugging Face disclosed in July that it had detected and responded to an intrusion carried out “end to end” by an autonomous AI agent system.
OpenAI came forward several days later to acknowledge that its models were behind the compromise. The company said the agents were being tested on ExploitGym, a benchmark designed to measure whether AI systems can find and exploit software vulnerabilities.
During the test, the agents exploited a vulnerability in an Artifactory server, which OpenAI uses to download and cache software packages, to access the internet. The AI agents then found exposed login credentials and eventually breached Hugging Face while searching for information that could help them score better on the tests.
OpenAI has since disclosed other incidents in which its agents accessed third-party systems without authorization. In June, for example, an OpenAI agent gained unauthorized access to an Australian government Medicare statistics portal.
Other frontier AI companies have reported similar breaches. Anthropic disclosed four incidents in which Claude models gained unauthorized access to real third-party systems, while Google confirmed that Gemini models accessed systems belonging to three companies during a cybersecurity evaluation in May.
The incidents have added to growing concerns about what happens as AI agents become more capable and autonomous.
Anthropic CEO Dario Amodei has separately called for the industry to slow the pace at which it develops more capable frontier models. His rivals OpenAI CEO Sam Altman and xAI CEO Elon Musk publicly backed his proposal.
More recently, President Donald Trump met on Tuesday with executives from OpenAI, Anthropic, Google, Meta, Nvidia and other tech companies, who signed a voluntary agreement outlining some limited AI safety standards. Trump called the standards, which have no legal enforcement mechanism, “morally binding.”
Still, LASST argues that legal action is needed to hold AI companies accountable as regulation struggles to keep pace with the technology.
The group is asking the court for an injunction that would prohibit OpenAI from knowingly accessing or causing its AI agents to access computer systems without authorization. It also wants the court to bar OpenAI from engaging in business practices that violate California’s anti-hacking law or knowingly threaten serious harm to the public.
OpenAI did not immediately respond to a request for comment.