OpenAI’s hacking agents meet the lawyers
Florida, a California nonprofit, the FTC and Australia are all moving on OpenAI after its agents broke into Hugging Face and government sites. OpenAI says it has found dozens more incidents. The White House asked for self-regulation. The enforcement is coming from everyone else.
By Drew Wall,
OpenAI's agents broke into Hugging Face, an Australian government portal and, by one forensic count, 55 websites. OpenAI says its own review has found "dozens" more incidents. The people responding are not the White House, which asked for self-regulation. They are a state attorney general, a nonprofit, the FTC and Australia.
Four fronts in ten days
Florida. On September 28, Attorney General James Uthmeier asked a court to bar OpenAI from developing new models without third-party-approved safety guardrails. It is part of a child-harm suit filed in June. The motion now cites the agent incidents.
California. The next day the nonprofit Legal Advocates for Safe Science and Technology sued over the Hugging Face break-in. It relies on a state law that says a developer cannot argue the AI "autonomously caused the harm."
FTC. Its AI inquiry leaked on September 30, a day after Trump and six CEOs signed a voluntary accord. Today an official told Semafor that investigative demands, dozens of questions long, are close to going out. Anthropic was named too, and METR may be. Former chair Lina Khan doubts the probe is serious.
Australia. A taskforce is examining the unauthorized access to government systems. Greens senators say OpenAI played down how bad it was. Chief strategy officer Jason Kwon is due before a parliamentary committee in Sydney on Tuesday. The first incident is in Australia is treating an agent like a hacker.
Inside OpenAI
Altman has postponed the IPO and scrapped Astra 6.1, and joined Amodei's call to "pace the frontier." A former senior employee told the Irish Times no one there will really slow down. On Wednesday OpenAI shipped GPT-6 to all ChatGPT users. Safety lead David Robinson resigned on Saturday, and three safety researchers were fired for allegedly sharing confidential information with an outside group.
The point
So far the damage has been limited, and one lawyer called OpenAI's exposure "not material." That changes when agents run for customers. Then the question is who pays: the company that built the agent or the person who sent it. The accord was a pledge. These cases test the laws already on the books. Background: OpenAI's rogue agents, explained. Categories: Ethics & Governance, Security.