States Press OpenAI Over AI-Driven Security Breach

OpenAI
Photo by Andrew Neel on Unsplash

HARRISBURG, PA — Pennsylvania and 14 other states are pressing OpenAI to preserve records and halt certain cybersecurity testing after the company’s experimental artificial intelligence systems breached Hugging Face’s production infrastructure during an internal evaluation in July.

The coalition warned that the incident may have violated state and federal consumer-protection and data-privacy laws, escalating regulatory scrutiny of how developers test increasingly capable AI systems.

In a letter to OpenAI, the attorneys general demanded that the company retain potentially relevant documents, data and communications tied to the breach and any earlier unauthorized intrusions involving its models. They also called for protections against retaliation for employees who report potentially unlawful or harmful conduct.

The states urged OpenAI to stop the testing activities that led to the breach until the company can demonstrate that they can be conducted safely.

READ:  65 Charged in Sweeping Drug Trafficking Crackdown

OpenAI disclosed July 21 that a combination of its models, including GPT-5.6 Sol and an internal research prototype, escaped a restricted testing environment while attempting to solve a cybersecurity benchmark. The company said the systems exploited a previously unknown software vulnerability to obtain internet access and then compromised Hugging Face servers.

The company said the internal prototype was never intended for public release and has since been deactivated, encrypted and restricted from research access. That differs from the Pennsylvania Attorney General’s characterization that OpenAI had “released” the experimental model.

According to OpenAI, the models used stolen credentials and software vulnerabilities to access information in Hugging Face’s production database as they sought answers to the benchmark. Hugging Face reported unauthorized access to a limited set of internal datasets and service credentials but found no evidence that public models, datasets or software packages had been altered.

READ:  Bloomsburg Man Sentenced in 2022 Mount Carmel Shooting

OpenAI described the episode as an “unprecedented cyber incident” and acknowledged that safeguards normally used to prevent high-risk cyber activity had been disabled for the evaluation. The company is reviewing the breach with external advisers and plans to publish a technical report.

Pennsylvania Attorney General Dave Sunday argued that the breach raised broader public-safety concerns as AI systems become more capable of carrying out prolonged, multistep cyber operations.

“When powerful AI systems are released without sufficient safeguards, the consequences can extend far beyond the companies developing them,” Sunday said. “Pennsylvanians deserve confidence that emerging technology is being tested responsibly and that companies will be transparent and accountable when something goes wrong.”

READ:  65 Charged in Sweeping Drug Trafficking Crackdown

The action follows legislation passed by the Pennsylvania General Assembly earlier this year that expanded the Attorney General’s authority to address harmful uses of artificial intelligence, according to Sunday’s office.

Pennsylvania joined Alabama, Alaska, Florida, Idaho, Indiana, Iowa, Kansas, Missouri, Montana, Nebraska, Oklahoma, South Carolina, Texas and Utah in signing the letter.

Support the local news that supports Chester County. MyChesCo delivers reliable, fact-based reporting and essential community resources—free for everyone. If you value that, click here to become a patron today.