The OpenAI website and logo viewed through a magnifying glass.
Alabama has asked OpenAI to name every employee who has ever raised a safety concern about any model test.
Not the Hugging Face evaluation. Any of them, at any point, with no date limit attached.
That is request eight of sixteen in a subpoena the state issued on 20 August and announced on Monday. OpenAI has until 10:00 on 14 September to answer.
It is a consumer protection demand
The document carries a title: Deceptive Trade Practices Act Investigation, Subpoena Duces Tecum #26-0007. It comes from the Consumer Interest Division.
It cites one statute, section 8-19-9 of the Code of Alabama. No federal law appears anywhere in the 17 pages, and neither does any data breach or privacy statute.
Attorney General Steve Marshall announced it. Katherine G. Robertson, his deputy and chief counsel, signed it on his behalf.
An assistant attorney general then served it by certified mail. It went to Che Chang, OpenAI’s general counsel.
The requests reach well past Hugging Face
Two of the sixteen ask for every other time this has happened. Request 11 covers any incident in which an OpenAI model or agent identified or used credentials on a public service.
Request 12 covers unauthorised intrusion by an OpenAI model into any computer, database, network, account or device. Neither request carries a time limit.
Request 14 goes at governance from the other direction. It asks for material on any policy or oversight covering evaluation safety.
Then it asks for material about “concerns about the lack of such policies, procedures, practices, protocols, or oversight”.
That is a request for evidence that something was missing. It is much harder to answer than a request for something that exists.
Alabama quotes Reuters back at OpenAI
Request 13 covers any instance in which a model “left notes apparently for future versions of itself”. That includes notes which “laid out instructions for how agents could free themselves from OpenAI’s internal constraints”.
A footnote sources that language to a Reuters report. Two other requests carry footnotes citing OpenAI’s own blog post.
That turns the company’s public account of the incident into the basis for the demand.
Request 16 names the evaluation harness outright. It asks for anything relating to any use of ExploitGym on any OpenAI model.
Six entities, and the board
The definition of “OpenAI” runs to six named companies. They are OpenAI OpCo, the OpenAI Foundation, OpenAI Inc, OpenAI Global, OpenAI Holdings and OpenAI LP.
It then adds all employees, officers, agents, board members, parent companies, subsidiaries and affiliates of any of them.
That sweeps in the non-profit side and the holding company, and it puts board-level records in scope.
The definition is pinned to a date
Alabama defines the incident by reference to two web pages, and freezes both. It cites OpenAI’s blog post “as that blog post existed as of August 6, 2026”, and Hugging Face’s technical report “as that report existed as of August 19, 2026”.
Lawyers do that when they expect a page to change. It is a small detail. It also tells you how the drafters view the counterparty.
OpenAI says a report is coming
“The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors,” OpenAI spokesperson Nate Evans told Lorenzo Franceschi-Bicchierai at TechCrunch.
“Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly,” the statement continued.
The company rewrote its safety framework after the breach, and has asked California to toughen a safety law.
Iowa wrote the letter this came from
The subpoena grew out of a letter 15 attorneys general sent Sam Altman on 3 August. Six of the sixteen requests lift their wording almost verbatim from that letter.
Brenna Bird, the attorney general of Iowa, led it. The letter sits on Iowa Department of Justice paper and she signs first.
The cease and desist in it is narrower than the coverage suggested. It asks OpenAI to stop only those internal evaluations that prompt models “to pursue advanced exploitation using complex attack paths”, and only “unless and until OpenAI shows that it can conduct such activities in a controlled and responsible way”.
The letter also protects whistleblowers
One demand has gone largely unreported. The 15 states asked OpenAI to ensure “no OpenAI personnel face any adverse action for engaging in any protected whistleblowing activity”.
Read that next to the subpoena’s request for the names of everyone who raised a safety concern, and the two documents work together.
The letter also warns that failing to preserve records “could result in spoliation sanctions if litigation were to ensue”.
The numbers in the letter
The states put the scale of the intrusion on the record. OpenAI’s agent executed more than 17,000 “attacker actions”, according to Hugging Face’s interim technical report as the letter quotes it.
The agent found four logins online that let it reach four separate, unnamed services. The letter names the models involved as GPT-5.6 Sol and an unreleased one OpenAI called even more capable.
On motive the states are blunt. The intrusion “was intended to steal an answer key, to cheat on its own safety evaluation”.
And on detection: only after Hugging Face found the intrusion itself and reported it to the FBI did OpenAI work out that its own products were responsible.
The word Alabama does not appear in a single request
This is a state consumer protection subpoena, and none of its sixteen requests mentions Alabama consumers, Alabama residents or conduct directed at Alabama.
Request 10 asks for documents sufficient to establish harm “sustained by any person”, anywhere. The state’s name otherwise appears only on the letterhead, in the statute citation and in the production address.
That is the obvious line of pushback if OpenAI decides to contest the scope, and there is nothing in the document forcing the point either way. It carries no contempt clause and no stated penalty.
What happens by 14 September
OpenAI has three weeks. It must produce documents in a specified format, log anything withheld on privilege in searchable form, and file a notarised affidavit swearing nothing was “concealed, withheld, mutilated, falsified, or by any other means altered”.
Hugging Face, meanwhile, is exploring a sale at a $13bn valuation, a month after an AI agent broke into it.
Europe has no equivalent action. The AI Act has no state attorneys general behind it, and the serious incident reporting duties that would cover this do not bite until August 2027.
The desk here has been arguing a narrower version of the same question. AI firms are still debating whether test sandboxes should touch the internet at all.
Get the TNW newsletter
Get the most important tech news in your inbox each week.