Alabama’s attorney general said on Monday the state had opened an investigation into OpenAI after one of its unreleased AI models breached the technology company Hugging Face in an unprecedented “lab leak” last month.Alabama Attorney General Steve Marshall announced the issuance of a subpoena on Aug. 24 demanding that OpenAI, led by Sam Altman, respond to an investigation into the company’s “complete lack of oversight and adequate safeguards” of “rogue AI.”OpenAI, the company that owns and develops the ChatGPT chatbot, said in a July 28 update that one of its unreleased artificial intelligence models bypassed restrictions in an evaluation environment and later accessed four accounts across four separate external services.OpenAI had been using that test environment to assess how capable its models were of carrying out cyberattacks as part of an internal safety evaluation. The incident was first revealed by AI startup Hugging Face, which stated on July 16 that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting on its own.Hugging Face CEO Clément Delangue called it “an attack unlike anything we’ve seen before.”“This is day one for cybersecurity in the age of agents & we’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” Delangue said in a July 22 post on X.An OpenAI agent also compromised a customer at a second tech company, New York-based Modal Labs. Modal executives said the company itself was not hacked.The investigation seeks to discover whether OpenAI violated Alabama’s Deceptive Trade Practices Act and other consumer protection laws.The attorney general’s subpoena requests that OpenAI respond with all potentially relevant documents, data, and information.“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical,” Marshall said.He said that the investigation seeks to uncover the facts and address hard truths about the threats that companies and consumers face from “rogue AI.”“Ultimately, I believe states have to act to protect their consumers while striking the appropriate balance to foster innovation and ensure America’s global competitiveness,” Marshall said.Alabama was part of a multi-state coalition that sent a letter earlier in the month to OpenAI demanding that it immediately cease and desist from all tests that led to this hacking, unless and until OpenAI shows that it can conduct such activities in a controlled and responsible way.Attorneys general from Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah signed the letter.Modal’s chief technology officer, Akshat Bubna, told The Epoch Times by email on July 31 that the agent exploited vulnerable code written by a customer and hosted on Modal’s platform.“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in any way,” he said.An OpenAI spokesman told The Epoch Times by email around the same time that this was “an unprecedented incident, and we think it marks an important moment for AI safety.”In a July 28 interview posted on X with venture capital firm founder Patrick O’Shaughnessy, Altman said that the Hugging Face security incident was the first he felt very “viscerally” about. “I’ve been a little surprised that more people don’t feel it so viscerally,” he said.“We paused training. We have to figure out how to secure our sandboxing in a world of multiple zero days being chained together. We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels,” he added.The Epoch Times contacted OpenAI and Hugging Face for comment.
Alabama Launches Rogue AI Probe Into ChatGPT After Hugging Face Lab Leak
Date:






