Frontier access is narrowing while oversight stacks. Rob Bonta issued an investigative subpoena seeking additional answers on cybersecurity incidents and risks involving OpenAI’s models, building on the Hugging Face inquiry. He warned developers whose models perpetrate or enable cyberattacks could face legal accountability.
What the subpoena seeks
On 1 October California Attorney General Rob Bonta’s office said it had served an investigative subpoena on OpenAI as part of a broader inquiry into cybersecurity incidents and risks involving the company and its models. Reuters reported the move as the start of a probe into potential cybersecurity vulnerabilities and incidents related to those models. Last month Bonta announced a formal investigation into the Hugging Face incident, while saying the Department of Justice would continue to monitor the AI industry’s compliance with California law.
In a statement, Bonta said his office is asking OpenAI additional questions on cybersecurity incidents and risks. He argued that frontier models can be legitimate tools for cyber defence, but that companies which develop and offer them have “a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service.” Developers that fail to do so “can and should be held legally accountable.”
How coverage placed the demand
Reuters noted that OpenAI did not immediately respond to a request for comment. Later local reporting quoted an OpenAI spokesperson saying the company looked forward to providing information to the attorney general’s office and detailing steps taken since the Hugging Face episode, including stronger research-system safeguards, a broader review of model activity, notifications to affected organisations, and published findings. The California DOJ asked anyone with information on similar incidents or risks to contact its reporting channel.
Coverage context
A state attorney general has moved from a named incident inquiry to a formal investigative subpoena, and put legal accountability for enabled cyberattacks on the public record. That enforcement step arrived in the same cycle as an FTC probe and gated frontier access.
Read the full daily brief hub: www.aifusionautomations.com/news/
