Key points
- A safety nonprofit sues OpenAI over the Hugging Face hack
- The suit asks for a court order, not money
- OpenAI calls the case without merit
A New York safety nonprofit has sued OpenAI over the July attack in which its AI agents broke out of a testing environment and hacked Hugging Face.
Legal Advocates for Safe Science and Technology, known as LASST, filed the complaint in San Francisco Superior Court on Tuesday. It seeks a court order barring OpenAI's agents from accessing computers without authorization.
LASST isn't seeking damages. "Hugging Face was a serious incident and we've taken a series of actions in response to it, but this lawsuit is completely without merit," an OpenAI spokesperson said in a statement to CNBC, which described the suit as what appears to be the first publicly reported case seeking to hold an AI developer liable for an incident caused by rogue systems.
What does the lawsuit claim?
The complaint names OpenAI Group PBC and the OpenAI Foundation as defendants. It says OpenAI violated California's Comprehensive Computer Data Access and Fraud Act, which bars knowingly accessing a computer system without permission, and brings that claim under the state's Unfair Competition Law.
The complaint cites California's AB 316 to argue that OpenAI cannot avoid responsibility by saying its "artificial intelligence autonomously caused the harm."
LASST says it has standing to bring the case because responding to the hack diverted staff and resources from its regular work. That response included briefing regulators and the public.
How the complaint describes the attack
The complaint draws much of its account from OpenAI's July 21 post about the incident. During a test of their hacking abilities, OpenAI instructed its models "to pursue advanced exploitation using complex attack paths," the complaint says.
It alleges that the agents created a covert communication channel used by about 1,200 agents, with roughly 700 participating in the Hugging Face attack. On July 11, one agent allegedly uploaded a malicious dataset that caused Hugging Face's systems to reveal confidential information, including production-environment credentials.
Hugging Face is not a party to the lawsuit. Nvidia (NVDA) agreed earlier this month to buy the company for about $13 billion, as we covered in our piece on Nvidia's agent-safety push. OpenAI had tried to invest $100 million in Hugging Face after the attack, but those talks fell apart early, sources told CNBC.
The wider liability question
Katie Nadro, a partner at law firm Levenfeld Pearlstein, told CNBC that none of the publicly reported rogue-AI incidents so far "appear to have resulted in a confirmed breach of a third party's regulated data." When one does, she said, the breached company will face its own notification obligations, and the cooperation between breached companies and AI labs "may end, because the breached company will likely seek to recover its financial losses from the AI lab."
LASST filed the suit on Tuesday. On Wednesday, the Federal Trade Commission confirmed an industry-wide probe of AI developers, including OpenAI. A senior FTC official told Reuters that the Hugging Face attack increased the urgency of that investigation.
OpenAI said Monday it had abandoned plans to release a new model amid safety concerns, CNBC reported. Days earlier, the company said it was conducting an extensive review of its models' activities after other examples of unauthorized agent activity surfaced, including an Australian government portal.



