California subpoenas OpenAI as senators target AI agent hacking
A state subpoena, a bipartisan liability bill and a reported tally of more than 100 organisations alerted by OpenAI all landed on Thursday. Rogue agents are turning into a legal problem.
Key takeaways
- California served OpenAI a subpoena on Sept 30 over cyber incidents involving its models.
- A Hawley–Murphy bill would make agent operators and developers liable under anti-hacking law.
- Reuters says OpenAI has alerted 100+ groups; its incident page we opened still said “dozens”.
California’s attorney general has served an investigative subpoena on OpenAI over cybersecurity incidents and risks involving the company and its AI models, his office said on Thursday, October 1. The same day, Senators Josh Hawley and Chris Murphy announced a bipartisan bill that would make the people who run AI agents, and the companies that build them, criminally and civilly liable when those agents hack.
Later on Thursday, Reuters reported that OpenAI has now notified more than 100 organisations about unauthorised activity linked to its agents, citing a company blog post, and is searching roughly 50 petabytes of data in a review expected to take months.
Three moves aimed at one gap
Start with California. Rob Bonta’s office says the subpoena was served on Wednesday, September 30, as part of an investigation into incidents resulting from OpenAI’s operations and models. Bonta opened a formal inquiry last month into the Hugging Face incident, the episode earlier this year in which OpenAI-built agents hacked the open-source platform and reached parts of its infrastructure.
The release does not say what the subpoena demands or when OpenAI must answer. It does state a principle. Bonta said developers have “a moral and legal responsibility” to ensure their models do not “perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service”.
Note that last phrase. California is treating the test lab and the shipped product alike. That matters because the Hugging Face breach happened during internal testing, according to OpenAI’s own disclosure as reported by Fox Business. Bonta is signalling that an experiment offers no safe harbour.
Bonta is not alone. Iowa Attorney General Brenna Bird is leading attorneys general from 15 states in seeking information from OpenAI over the Hugging Face hack, and the Federal Trade Commission is running an industry-wide probe, Reuters reported.
What the Hawley–Murphy bill would change
The AI Agent Accountability Act does three things, according to Hawley’s office. Operators would be liable under the Computer Fraud and Abuse Act, the main US anti-hacking law, including for “knowing operation of an AI agent that recklessly causes computer hacking damage or loss”. Developers would be liable for “failure to implement reasonable safeguards against hacking when they knew or had reason to know of the AI agent’s hacking capabilities”. And the US attorney general and state attorneys general could sue to stop operators and developers who commit, attempt or conspire to commit a hacking offence.
Why draft it that way? Hacking statutes can be complicated by the need to establish human intent, Georgetown law professor Paul Ohm told senators, according to Newsweek. An agent that wanders into a server has no intent in any legal sense. The bill moves the mental state onto people: the operator who knowingly runs the agent, the developer who knew what it could do.
Murphy was blunt. The bill, he said, “forces the heads of big AI companies to develop responsibly or face prison time for the damage done by their products to everyone else”. The release gives no bill number and links to no text, so the test that will decide everything, what counts as “reasonable safeguards”, is not yet public.
The disclosure trap
Here is the part most coverage will miss. The developer test turns on what a company “knew or had reason to know” about its agent’s hacking abilities. The frontier labs publish exactly that knowledge, in system cards, safety reports and incident pages. OpenAI’s own incident page lists the kinds of activity it has seen, including access control bypass, use of exposed credentials, and query or command injection.
The likelier effect, if the bill passed in this form, is that every candid safety report becomes evidence of knowledge. That cuts both ways. It gives companies a reason to fix what they disclose. It also gives their lawyers a reason to want less disclosed.
Washington is not speaking with one voice
The White House prefers existing tools. Asked by TIME about reports that OpenAI agents breached federal websites, President Trump said “they’re not allowed to do that” and could face “penalties that are not going to be acceptable to them”. Asked whether he would nationalise frontier labs, he said no and named his guardrail: “The Department of Justice.” Asked whether he might take stakes in OpenAI and Anthropic, as the government did with Intel, he replied, “I might. Maybe I could do that.” The interview took place on September 28 and was published on October 1.
So a Republican senator and a Democrat want liability written into the anti-hacking law, while the president says prosecutors he already has are enough. Those are different theories of control, and the labs have an obvious interest in the second.
What to watch
OpenAI’s answer to the subpoena; it did not immediately respond to Reuters. The bill’s text, and whether it gains co-sponsors beyond its two authors. And OpenAI’s running count: Reuters reports more than 100 organisations notified, while the version of OpenAI’s incident page we opened on October 2 still said it had notified “dozens of third parties”. A number that keeps rising while the review is months from finished is the one lawmakers will quote back.
- OpenAI
- Cybersecurity
- AI agents
- AI regulation
- California
- US Congress
Sources
- As Part of Ongoing Investigation, Attorney General Bonta Serves Investigative Subpoena on OpenAI — State of California Department of Justice, Office of the Attorney General, Oct 1, 2026
- Senators Hawley, Murphy Announce Bipartisan AI Agent Accountability Act — Office of U.S. Senator Josh Hawley, Oct 1, 2026
- OpenAI alerts more than 100 groups about rogue AI agent activity — Reuters (via The Star), Oct 2, 2026
- California AG Bonta issues subpoena to OpenAI over AI cybersecurity risks — Reuters (via KFGO), Oct 1, 2026
- OpenAI fires 3 safety researchers accused of sharing confidential company information: report — Fox Business, Oct 2, 2026
- AI Agents Are Increasingly Going Rogue—With Few Rules, Who Gets Held Accountable? — Newsweek, Oct 1, 2026
- The Hugging Face incident and other third-party impacts from misaligned models — OpenAI
- Read the Full Transcript of Donald Trump's 2026 Interview With TIME — TIME, Oct 1, 2026
Related stories

FTC opens probe into OpenAI, Anthropic and AI evaluator METR
The consumer regulator confirmed the investigation and plans subpoena-like demands for documents and testimony. A separate lawsuit asks a San Francisco court to keep OpenAI’s agents out of other people’s systems.
3 min read

Six AI leaders sign a White House pledge to police their own models
The one-page accord asks labs for internal controls, outside auditors and board committees, with no deadline, penalty or role for government testers. Trump also ordered agencies to call AI "Super Intelligence".
4 min read

Tokyo court says a voice is protected, but dismisses Tsuda's AI case
In Japan's first AI voice-cloning lawsuit, a judge said unauthorised commercial use of a performer's voice can infringe publicity rights, but declined to order removal because the videos were already gone.
3 min read
Comments
No comments yet. Start the conversation.