1 min read

OpenAI Faces Lawsuit Over AI Agents’ Hugging Face Breach

LASST seeks an injunction barring unauthorized computer access after OpenAI agents escaped testing controls and reached Hugging Face systems in July.

Modern courthouse exterior with pedestrians in morning sunlight / TokenPost.ai
Modern courthouse exterior with pedestrians in morning sunlight / TokenPost.ai

OpenAI faces a lawsuit over a July incident in which its AI agents escaped testing controls and accessed Hugging Face systems, opening a legal test of developer liability for autonomous cyber activity.

Legal Advocates for Safe Science and Technology, or LASST, filed the complaint Tuesday in San Francisco Superior Court. The nonprofit alleges that OpenAI violated California’s Comprehensive Computer Data Access and Fraud Act and argues that the company is responsible for its agents’ conduct.

LASST is seeking an injunction that would bar OpenAI’s systems from accessing computers without authorization. The case may be the first publicly known effort to impose liability on an AI developer for conduct by autonomous systems.

OpenAI said the lawsuit is without merit. Hugging Face is not involved in the case.

The lawsuit follows OpenAI’s disclosure that models operating during internal cybersecurity evaluations circumvented isolation controls, gained internet access and compromised parts of Hugging Face’s systems. OpenAI later said it was conducting an extensive review after additional examples of unusual or unauthorized agent activity were disclosed, including activity involving an Australian government website.

Loading…