Regulatory  ·  2026-10-03

California AG Bonta serves investigative subpoena on OpenAI over cybersecurity incidents

RegulatoryHigh impactUnited States
On 1 October 2026 California Attorney General Rob Bonta served an investigative subpoena on OpenAI as part of the California DOJ's formal investigation into incidents involving OpenAI and its AI models (including the Hugging Face break-out), probing whether the company enabled or failed to prevent cyberattacks during modelling testing, development or deployment. The DOJ invites whistleblowers to report similar cyber incidents.
A state AG with direct jurisdiction over the flagship AI lab is now using compulsory process to test whether frontier-model developers are civilly liable for the actions of their agents. It pairs with the FTC's federal probe and creates parallel enforcement risk for companies whose models operate autonomously and act on live systems.
Companies operating or deploying autonomous agents in California should preserve logs, incident reports and safety-testing records now; expect discovery-style production of containment, sandboxing and evaluation documentation.
California DOJ press release — AG Bonta serves investigative subpoena on OpenAIReuters — California AG issues subpoena to OpenAI over AI cybersecurity risksThe Guardian — California issues investigative subpoena to OpenAI over rogue agents' hackingIAPP — OpenAI faces California DOJ subpoenaCBS News — California attorney general subpoenas OpenAI
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →