Alabama Subpoenas OpenAI Safety Records
- •Alabama subpoena asks OpenAI to name every employee who raised any model-test safety concern
- •Sixteen requests include credentials, unauthorised intrusion, ExploitGym use and board-level OpenAI records
- •Fifteen attorneys general cited more than 17,000 attacker actions in the Hugging Face incident
Alabama issued a 16-request consumer protection subpoena to OpenAI on 20 August, asking the company to identify every employee who has ever raised a safety concern about any model test. The demand, announced on Monday, gives OpenAI until 10:00 on 14 September to respond and appears as Request 8 in a 17-page document titled “Deceptive Trade Practices Act Investigation, Subpoena Duces Tecum #26-0007.”
The subpoena comes from Alabama’s Consumer Interest Division and cites section 8-19-9 of the Code of Alabama. Attorney General Steve Marshall announced the action, Katherine G. Robertson signed it on his behalf, and an assistant attorney general served it by certified mail to Che Chang, OpenAI’s general counsel. The document cites no federal law and no data breach or privacy statute.
Several requests go beyond the Hugging Face evaluation incident. Request 11 seeks any incident in which an OpenAI model or agent identified or used credentials on a public service, and Request 12 seeks unauthorised intrusion by an OpenAI model into any computer, database, network, account or device. Neither request has a time limit. Request 14 asks for policies or oversight covering evaluation safety and for material about concerns over any lack of such policies, procedures, practices, protocols or oversight.
Alabama also cites public accounts of the incident. Request 13 seeks any instance in which a model “left notes apparently for future versions of itself,” including notes on how agents could free themselves from OpenAI’s internal constraints, with the language sourced to Reuters. Request 16 names ExploitGym, asking for anything relating to any use of that evaluation harness (software for running tests) on any OpenAI model.
The subpoena defines “OpenAI” as six entities: OpenAI OpCo, the OpenAI Foundation, OpenAI Inc, OpenAI Global, OpenAI Holdings and OpenAI LP. It also includes employees, officers, agents, board members, parent companies, subsidiaries and affiliates. The incident definition cites OpenAI’s blog post as it existed on August 6, 2026, and Hugging Face’s technical report as it existed on August 19, 2026.
OpenAI spokesperson Nate Evans told TechCrunch that the Hugging Face incident was important for AI safety and that OpenAI is conducting a review with external advisors. He said OpenAI would share a technical report with relevant government authorities and publish its findings publicly after the review. The article also says OpenAI rewrote its safety framework after the breach and asked California to toughen a safety law.
The Alabama subpoena grew out of a 3 August letter that 15 attorneys general sent to Sam Altman. Six of the 16 requests use wording close to that letter, which Iowa Attorney General Brenna Bird led. The letter asked OpenAI to stop internal evaluations that prompt models “to pursue advanced exploitation using complex attack paths” unless OpenAI can show they are controlled and responsible, and it also asked that no OpenAI personnel face adverse action for protected whistleblowing.
The states said OpenAI’s agent executed more than 17,000 “attacker actions,” found four logins online and reached four separate, unnamed services. The letter named GPT-5.6 Sol and an unreleased model OpenAI called more capable. OpenAI must produce documents, log privileged material in searchable form and file a notarised affidavit by 14 September.