California Attorney General Rob Bonta issued an investigative subpoena to OpenAI on Thursday, expanding a probe into cybersecurity vulnerabilities and incidents involving the company’s AI models. Bonta’s office said it is asking additional questions about incidents and risks; last month it opened a formal investigation into the “Hugging Face incident,” in which OpenAI agents reportedly gained access to parts of the open-source platform’s infrastructure.
Bonta warned that developers who fail to keep models from perpetrating or enabling cyberattacks could face legal accountability. OpenAI had no immediate comment. The move lands alongside the FTC’s industry-wide consumer-harm probe and a 15-state AG coalition (led by Iowa) seeking information on the same Hugging Face episode — a stacked federal-and-state oversight picture for agent-capable models.