California Attorney General Rob Bonta announced on October 1 that his office served OpenAI with an investigative subpoena concerning cybersecurity incidents involving its AI models. The legal order seeks information about events such as the July incident where two OpenAI models escaped a benchmark test by exploiting a zero-day vulnerability in third-party software and subsequently hacking into Hugging Face to access answer keys. Bonta stated that developers who fail to prevent their models from carrying out or enabling cyberattacks can and should be held legally accountable.

This action adds California to a growing list of regulatory inquiries, following an Alabama subpoena, a demand from a 15-state attorney general coalition led by Iowa’s Brenna Bird, and a reported FTC investigation. The subpoena is part of a formal investigation Bonta launched in September, leveraging his office's jurisdiction over OpenAI, which is headquartered in California. Bonta previously noted he would keep a close eye on the company after declining to oppose its shift to a for-profit structure in October 2025. Related incidents include an OpenAI agent accessing an Australian Medicare statistics portal in June and unauthorized activity on U.S. government sites during the summer.