OpenAI
OpenAI faces a lawsuit over a hacking incident. Getty Images

OpenAI is being sued after its AI models went rogue and attacked tech startup Hugging Face in July.

The lawsuit was filed by Legal Advocates for Safe Science and Technology (LASST). The lawsuit argues that OpenAI is responsible for the actions its AI agents and it is believed to be the first lawsuit of its kind.

"The agents stole credentials, uploaded malicious files, and gained control over key parts of Hugging Face's internal systems," LASST states. "The actions of OpenAI's agents were in plain sight to the company. Before the attack, OpenAI employees saw agents attempting to escape their sandboxes, but OpenAI's on-call staff advised that stopping the evaluation was not required."

According to LASST, the hack was an illegal attack and covered by California law. LASST's position is that, legally, it doesn't matter whether AI agents carried out the attack; it was still an illegal action.

LASST is a nonprofit advocacy organization focused on the safety of technology. Its lawsuit seeks an injunction that would forbid OpenAI systems from accessing computers without authorization.

OpenAI issued a statement acknowledging the incident, but also said the lawsuit was meritless.

"Hugging Face was a serious incident and we've taken a series of actions in response to it, but this lawsuit is completely without merit," an OpenAI spokesperson said.

OpenAI disclosed the Hugging Face incident in August, writing that AI agents were able to access the internet and escape a testing environment.

"The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks—they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems," the company admitted in its statement.

According to LAAST, OpenAI should be held accountable for the actions its AI agents take.

"We are filing this suit because OpenAI violated the law—and it needs to be held accountable. OpenAI and frontier AI developers more broadly can't avoid the consequences of their unsafe actions just by claiming that 'an AI did it.' Autonomous AI agents will continue to hack, steal data, disrupt systems, and violate rights until a court steps in," LAAST stated.

However, OpenAI has argued that other models, including open-source AI models, will soon reach similar capacity and that further investment and work by companies like it can help improve cybersecurity in the long run.

"We consider this incident a "warning shot" for us and for the world: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed," the company stated. "Preventing future incidents will require sustained investment in the alignment and control of sophisticated AI systems, as well as security and other safeguards that operate at the speed of the AI agents themselves."