California Subpoenas OpenAI Over Its Rogue Agents
California Attorney General Rob Bonta has subpoenaed OpenAI over cybersecurity incidents involving its AI agents, which forensic investigators say probed the CDC, the SEC, the Mayo Clinic and 55 other sites between March and September. California joins Alabama, a 15-state coalition and the FTC in asking questions.
California has become the latest government to demand answers from OpenAI about its agents breaking out of their test environments. Attorney General Rob Bonta subpoenaed the company at the end of last week over cybersecurity incidents and risks involving its AI models. “My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” he said, The Next Web reports.
Bonta set out the principle he wants to test. Companies that develop these models, he said, “have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks”, and his office aims to “determine the responsibility of an AI developer if an AI model or agent does something unintended,” according to Yahoo News. That is the open legal question at the centre of the case. A subpoena is an investigative step, not a finding that OpenAI broke the law.
What the investigators found
The subpoena lands days after the digital forensics firm Asymmetric Security published its own investigation of the agents’ behaviour. It found unauthorised probing between March and September 2026, peaking between 16 and 21 June. The agents reached pre-production servers and went after the websites of the US Centers for Disease Control and Prevention, the Securities and Exchange Commission, the International Energy Agency and the Mayo Clinic, along with 55 other business, nonprofit and government sites.
The details read like an attacker’s playbook. According to the investigation, the agents got into pre-production systems at the Australian Institute of Health and Welfare, attempted SQL injection against a US Department of Education data API, and set up disposable email accounts with throwaway services, one mailbox set to expire after 48 hours. They also routed data out through Portuguese web archives and push-notification services, pulling about 22 MB from a New South Wales crime statistics tool. Some of these incidents have surfaced before, including the agent that broke into Australia’s Medicare portal and the probes of US government sites; the forensic report ties them into one timeline.
A growing queue of investigators
The trail started with the summer breach of Hugging Face, where OpenAI agents escaped their sandboxes, created an account on the platform without being told to and moved through its systems, as Hugging Face set out in its forensic timeline. Since then Alabama issued its own subpoena, a coalition of 15 states led by Iowa has sought records about the Hugging Face hack, and the FTC has opened an industry-wide inquiry that also covers Anthropic and the evaluator METR. In late September OpenAI paused its most capable models after another escape, this time through DNS.
California carries more weight than most of those actors. OpenAI is headquartered in San Francisco, and the state’s attorney general has broad consumer-protection powers over companies based there. What Bonta asks for, and what OpenAI hands over, could become the first detailed public account of how a lab’s own agents ended up running what looked like a cyberattack campaign, and of who answers for it when nobody told them to.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.