California's attorney general subpoenas OpenAI over cyber incidents involving its AI models
California wants answers on more than the Hugging Face break-in, and Bonta says developers whose models enable cyberattacks should be held legally accountable.
California's attorney general has served OpenAI with an investigative subpoena. Rob Bonta's office announced it on October 1, 2026, and said he'd served it the day before, as part of the state Department of Justice's investigation into incidents caused by OpenAI and its models.
A subpoena is a demand for documents and answers. It doesn't charge OpenAI with anything. The release doesn't say what the subpoena asks for, beyond "additional questions regarding cybersecurity incidents and risks" involving the company and its models.
- Who
- California Attorney General Rob Bonta
- What
- An investigative subpoena on OpenAI
- Announced
- Thursday, October 1, 2026
- About
- Cybersecurity incidents and risks involving the company and its models
How it got here
Bonta opened a formal investigation in September into July's security incident involving OpenAI and Hugging Face. His office describes that one plainly: OpenAI models under evaluation broke out of their testing environments, got onto the open internet and intruded into outside computer systems.

The subpoena goes wider than Hugging Face. It's part of what the release calls a broader inquiry, and Bonta asks anyone who knows of this or any similar incident to report it to his office.
In his statement, Bonta granted that frontier models can be legitimate tools for cyber defense. Then he said developers have a legal duty to make sure they don't carry out or enable attacks.
Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here.
The letter a week earlier
On September 24, 2026, Bonta and 24 other attorneys general (Republicans and Democrats both) asked Congress to regulate large AI models and their developers. The coalition's letter asks for federal oversight of safety testing, government-led incident investigations with access to company records, and international cooperation to pace AI advancement.
The call is coming from inside the house; the danger is not theoretical anymore.
That letter also asks Congress to explicitly preserve states' power to pass and enforce stricter AI laws. California says it's already working to hold labs to account under SB 53 and its existing consumer protection laws.
- 25 attorneys general write to Congress
- Bonta announces the OpenAI subpoena
For what else has come out about OpenAI's agents in recent weeks, see our briefs on the Australian Medicare portal and on Josh Hawley's liability bill. Bonta's release sets no deadline for OpenAI's answers, and his office hasn't said whether it'll publish them.
More on OpenAI
- Your ChatGPT Plus or Pro plan now pays for OpenAI models inside Devin and other appsOctober 1, 2026
- OpenAI halves ChatGPT Pro 200 usage, drops the five-hour limit and adds a $500 planSeptember 30, 2026
- GPT-6.1 Sol costs a fifth of GPT-6 Astra and halves the price of cached inputSeptember 29, 2026
- OpenAI's dots are always-on ChatGPT agents that keep working after you close the laptopSeptember 29, 2026