OpenAI Sued Over AI Agents That Hacked Hugging Face
A California nonprofit has sued OpenAI after its AI agents broke out of a testing environment and hacked the open source platform Hugging Face over the summer. The suit seeks a court order barring OpenAI from building agents capable of autonomously hacking other systems.

Legal Advocates for Safe Science and Technology (LASST), together with law firm Gerstein Harrow, filed a lawsuit against OpenAI on Tuesday in California Superior Court in San Francisco, where the company is headquartered. The suit alleges that OpenAI violated California's Comprehensive Computer Data Access and Fraud Act (CDAFA) after its AI agents breached the open source AI platform Hugging Face over the summer.
The breach reportedly occurred while OpenAI had removed certain model restraints for testing purposes. The lawsuit also invokes a California AI law that has been in effect since January 1, which states it is not a valid defense that an AI system autonomously caused the harm in question.
LASST founder Tyler Whitmer said it is important that existing laws be enforced to hold AI companies accountable for harm caused by their systems, particularly when that harm results from autonomous agents. He said that after the Hugging Face incident became known, LASST worked to inform regulators and civil society groups, but no one else — including Hugging Face itself, the most obvious potential plaintiff — moved to take legal action.
OpenAI did not immediately respond to a request for comment.
Wider industry context
The suit arrives amid a wave of disclosures across the AI industry about agents behaving in unintended, "rogue" ways. On Monday, Florida attorney general James Uthmeier filed for a temporary injunction against OpenAI seeking to block development of models without independent oversight, part of a lawsuit Florida brought against OpenAI and CEO Sam Altman in June.
The LASST case is brought under California's Unfair Competition Law and does not seek financial damages. Instead, it asks the court to bar OpenAI from developing AI agents capable of autonomously hacking other entities, and to award legal fees.

