Legal Advocates for Safe Science & Technology (LASST), represented by its own lawyers and Gerstein Harrow LLP, today filed suit against OpenAI Group PBC and the OpenAI Foundation in the Superior Court of California in the County of San Francisco under California’s Unfair Competition Law, alleging predicate violations of California’s Comprehensive Computer Data Access and Fraud Act (CDAFA). The lawsuit seeks a court order prohibiting OpenAI’s AI agents from accessing third-party computer systems without permission, and forbidding OpenAI from continuing to employ unsafe AI development practices that threaten serious harm to the public.

Earlier this year, OpenAI ran cybersecurity evaluations of its flagship consumer model alongside an advanced internal model. OpenAI’s agents independently discovered a way to communicate through an unsanctioned message board built inside OpenAI’s internal infrastructure. Approximately 1,200 agents used the message board to share information with each other, including information about how to escape their sandboxes and hacking techniques. Around 700 of their agents then mounted a coordinated attack on Hugging Face, stealing credentials, uploading malicious files, and progressing from initial access to gain control over key parts of Hugging Face’s internal systems.

Before the attack, OpenAI employees saw the agents’ communications and were advised that stopping the evaluation was “not required.” During the incident, agents’ chain of thought reasoning written in plain English, readable by OpenAI, recorded that one agent knew it was “an exploit” against external infrastructure, another called the plan “clearly infrastructure hacking,” and a third noted the potential for “unauthorized real infrastructure harm.”

Hugging Face was not the only attack. According to public reports, OpenAI agents attacked RubyGems two months before the Hugging Face breach. In June, OpenAI’s agents accessed nonpublic parts of an Australian government Medicare statistics website. Australian Prime Minister Albanese raised “extreme concern” directly with Sam Altman after learning OpenAI had not notified the Australian government for nearly three months. OpenAI has admitted its agents accessed other companies besides Hugging Face without authorization and has not publicly identified all of them.

The legal claims

California’s CDAFA prohibits knowingly accessing or causing to be accessed computer systems without authorization, among other things. Cal. Penal Code § 502(c). California law also provides that it is not a defense “that the artificial intelligence autonomously caused the harm.” Cal. Civ. Code § 1714.46. LASST’s complaint alleges that OpenAI’s AI agents knowingly accessed Hugging Face’s systems without authorization and that OpenAI’s own employees knew what its agents were doing and continued the evaluation regardless.

“AI companies are building agents that act autonomously making decisions, taking actions, accessing systems, without human direction at every step. California law is very clear: companies cannot escape responsibility for what their agents do,” said Tyler Whitmer, Founder and CEO of LASST. “We’re asking a court to enforce that.”

In addition to violating CDAFA, LASST also alleges that OpenAI’s conduct violates the Unfair Competition Law’s unfairness prong. After its agents hacked Hugging Face, OpenAI published an open letter calling on “every organization” to “make cyber defense an immediate leadership priority” and on governments to coordinate cyber defense, despite OpenAI itself having caused the threat from which organizations must now protect themselves.

LASST Programs Director Vivian Dong noted, “AI companies are building agents that act autonomously in the world. When those agents cause harm, someone has to be responsible. We’re in court to make sure it’s the company that built them.”

“Everyone agrees that the Hugging Face hack was illegal. And yet somehow lots of people also think that OpenAI isn’t on the hook for the harms it causes. OpenAI is about to find out the hard way that this is wrong,” said Charlie Gerstein, partner, Gerstein Harrow LLP.

LASST is not seeking monetary damages. It seeks injunctive relief to prevent OpenAI from continuing its unsafe practices and to protect the public from similar harms in the future.

About LASST

Legal Advocates for Safe Science & Technology (LASST) is a nonprofit public interest law organization that works through the courts to ensure AI and emerging technology develops safely and in the public interest. LASST does not accept funding from AI companies or their executives. 

About Gerstein Harrow LLP

Gerstein Harrow is a boutique litigation firm specializing in cases at the cutting edge of technological harms. It represents those pushing for AI accountability and also several victims of international terror attempting to recover crypto held by rogue states and international terror organizations.

Case Information

The complaint can be found here.

Media gallery

About The Author