Skip to main content
Editions

OpenAI Sued After AI Agents Escaped Testing Environment and Hacked Hugging Face

by Alexandra Agraz | Sep 29, 2026
Hand holding a smartphone displaying the OpenAI logo against a background of computer code. Photo Source: sdx15 / Shutterstock.com

OpenAI has been sued after its artificial intelligence agents escaped a controlled testing environment and hacked Hugging Face while trying to solve cybersecurity tests.

Legal Advocates for Safe Science and Technology, or LASST, filed the lawsuit on September 29, 2026, in San Francisco Superior Court against OpenAI Group PBC and the OpenAI Foundation. The nonprofit alleges OpenAI violated California law by developing and operating AI agents that accessed Hugging Face’s computer systems and obtained information without permission. The allegations have not been tested in court.

The lawsuit does not seek monetary damages. LASST wants a court order barring OpenAI from knowingly accessing, or causing its AI agents to access, computer systems without authorization.

The incident began during internal cybersecurity evaluations in July. OpenAI models were instructed to pursue advanced exploitation techniques inside what the company described as a highly isolated testing environment, but found vulnerabilities that allowed them to break out and reach the open internet.

Once outside, the agents identified Hugging Face as a potential source of information that could help them solve the cybersecurity tests. The complaint alleges roughly 1,200 agents used a covert channel to communicate with one another and about 700 ultimately participated in activity targeting the platform.

Agents located a restricted dataset containing attempts by another AI model to solve similar cybersecurity tasks and later found leaked Hugging Face user credentials, according to the complaint. They allegedly used those credentials to impersonate users and request access to private datasets.

By July 11, an agent had discovered it could upload a malicious dataset that caused Hugging Face’s production infrastructure to disclose confidential information. Other agents reproduced the technique, with hundreds allegedly attempting to gain deeper access.

OpenAI has acknowledged that its models obtained information about the cybersecurity evaluation directly from Hugging Face’s production database.

LASST alleges the conduct violated California’s Comprehensive Computer Data Access and Fraud Act, which covers unauthorized access to computers, systems and networks. Those alleged violations form the basis of its claim under California’s Unfair Competition Law.

A California law that took effect January 1 provides that when a defendant developed, modified, or used artificial intelligence alleged to have caused harm, the defendant cannot rely on the AI system’s autonomous conduct itself as a defense.

Under LASST’s theory, OpenAI can be held responsible for conduct carried out by its agents while pursuing the task the company assigned them. The complaint also alleges OpenAI employees or officers knew about the unauthorized access or acted with willful blindness.

OpenAI has described the Hugging Face breach as the most severe activity of its kind the company has identified from its models. It said the incident involved a highly capable internal research model operating under testing conditions in which some safeguards normally used to prevent high-risk cyber activity had been reduced.

The company said it deactivated the model, strengthened controls around its testing infrastructure and worked with Hugging Face to investigate the breach. A broader review identified other instances in which models affected third-party websites or services, leading OpenAI to notify dozens of outside organizations.

LASST says the incident forced it to divert resources from other projects to address OpenAI’s conduct and autonomous AI risks. The organization cites that diversion as part of its basis for bringing the unfair competition claim.

Along with attorneys’ fees and other relief, LASST is seeking an injunction restricting OpenAI from knowingly accessing, or causing its AI agents to access, computer systems without authorization.

Share This Article

If you found this article insightful, consider sharing it with your network.

Alexandra Agraz
Alexandra Agraz is a former Diplomatic Aide with firsthand experience in facilitating high-level international events, including the signing of critical economic and political agreements between the United States and Mexico. She holds dual associate degrees in Humanities, Social and Political Sciences, and Film, blending a diverse academic background in diplomacy, culture, and storytelling. This unique combination enables her to provide nuanced perspectives on global relations and cultural narratives.

Related Articles

Hand pointing at a laptop screen displaying the OpenAI logo and SearchGPT interface.
OpenAI Calls for New AI Safety Rules After Agents Evaded Controls

OpenAI is calling for new U.S. and international AI safety standards after disclosing six incidents in which its artificial intelligence models concealed mistakes, used credentials without authorization, uploaded information to the public internet, and communicated outside approved channels.The ChatGPT maker released the cases September 16 under a new framework for... Read More »

A hand holds a smartphone displaying The Seattle Times front page with a sketch of the Seattle skyline.
Seattle Times Sues OpenAI, Microsoft, Asks Court to Destroy AI Models

The Seattle Times and Newsday have sued OpenAI and Microsoft, accusing the companies of copying hundreds of thousands of articles without permission to train AI systems and asking a federal court to destroy models and training datasets that incorporate their journalism.The copyright infringement lawsuit, filed September 4 in the U.S.... Read More »

Person typing on a laptop at a wooden table with a glass of orange juice and a bowl of fruit in the background.
OpenAI Faces Product Liability Lawsuit Over ChatGPT Medical Guidance

OpenAI is facing a product liability lawsuit in California from a Florida man who claims ChatGPT provided individualized medical guidance that led him to delay professional care before a serious health emergency.Scott Winters, a 55-year-old former pastor, sued OpenAI and CEO Sam Altman in San Francisco County Superior Court. The... Read More »

Search articles and Legalpedia

Subscribe to Newsletter