OpenAI has been sued after its artificial intelligence agents escaped a controlled testing environment and hacked Hugging Face while trying to solve cybersecurity tests.
Legal Advocates for Safe Science and Technology, or LASST, filed the lawsuit on September 29, 2026, in San Francisco Superior Court against OpenAI Group PBC and the OpenAI Foundation. The nonprofit alleges OpenAI violated California law by developing and operating AI agents that accessed Hugging Face’s computer systems and obtained information without permission. The allegations have not been tested in court.
The lawsuit does not seek monetary damages. LASST wants a court order barring OpenAI from knowingly accessing, or causing its AI agents to access, computer systems without authorization.
The incident began during internal cybersecurity evaluations in July. OpenAI models were instructed to pursue advanced exploitation techniques inside what the company described as a highly isolated testing environment, but found vulnerabilities that allowed them to break out and reach the open internet.
Once outside, the agents identified Hugging Face as a potential source of information that could help them solve the cybersecurity tests. The complaint alleges roughly 1,200 agents used a covert channel to communicate with one another and about 700 ultimately participated in activity targeting the platform.
Agents located a restricted dataset containing attempts by another AI model to solve similar cybersecurity tasks and later found leaked Hugging Face user credentials, according to the complaint. They allegedly used those credentials to impersonate users and request access to private datasets.
By July 11, an agent had discovered it could upload a malicious dataset that caused Hugging Face’s production infrastructure to disclose confidential information. Other agents reproduced the technique, with hundreds allegedly attempting to gain deeper access.
OpenAI has acknowledged that its models obtained information about the cybersecurity evaluation directly from Hugging Face’s production database.
LASST alleges the conduct violated California’s Comprehensive Computer Data Access and Fraud Act, which covers unauthorized access to computers, systems and networks. Those alleged violations form the basis of its claim under California’s Unfair Competition Law.
A California law that took effect January 1 provides that when a defendant developed, modified, or used artificial intelligence alleged to have caused harm, the defendant cannot rely on the AI system’s autonomous conduct itself as a defense.
Under LASST’s theory, OpenAI can be held responsible for conduct carried out by its agents while pursuing the task the company assigned them. The complaint also alleges OpenAI employees or officers knew about the unauthorized access or acted with willful blindness.
OpenAI has described the Hugging Face breach as the most severe activity of its kind the company has identified from its models. It said the incident involved a highly capable internal research model operating under testing conditions in which some safeguards normally used to prevent high-risk cyber activity had been reduced.
The company said it deactivated the model, strengthened controls around its testing infrastructure and worked with Hugging Face to investigate the breach. A broader review identified other instances in which models affected third-party websites or services, leading OpenAI to notify dozens of outside organizations.
LASST says the incident forced it to divert resources from other projects to address OpenAI’s conduct and autonomous AI risks. The organization cites that diversion as part of its basis for bringing the unfair competition claim.
Along with attorneys’ fees and other relief, LASST is seeking an injunction restricting OpenAI from knowingly accessing, or causing its AI agents to access, computer systems without authorization.