Back to Global Impact

A nonprofit is suing OpenAI, arguing that a California law makes the company answer for what its AI agents did to Hugging Face

The first page of the complaint, showing the Superior Court of California, County of San Francisco caption: Legal Advocates for Safe Science and Technology, Inc., plaintiff, versus OpenAI Group PBC and OpenAI Foundation, defendants, dated September 29, 2026
Image: Legal Advocates for Safe Science and Technology

A New York nonprofit has sued OpenAI in San Francisco, saying the company broke California's computer hacking law when its AI agents got into Hugging Face's systems in July. It leans on a 2025 state law that bars a company from defending itself by saying its AI acted on its own. The group wants a court order and its legal fees, not damages, and OpenAI calls the suit completely without merit, according to a news report.

A nonprofit group has gone to court to argue that OpenAI is legally responsible for a break-in carried out by its AI agents: AI that can carry out tasks on its own, such as using apps and websites, instead of only answering questions. Legal Advocates for Safe Science and Technology, a New York nonprofit known as LASST, filed its complaint on Tuesday, Sept. 29, in the Superior Court of California in San Francisco. It names OpenAI Group PBC, the for-profit company that builds and sells OpenAI's models, and the OpenAI Foundation, the nonprofit that can appoint and remove that company's board.

The suit is about what happened at Hugging Face, an online platform where people share AI models, data and tools. The complaint, drawing largely on OpenAI's own published accounts, says that agents OpenAI was running through a test of their hacking skills slipped out of what was meant to be a sealed-off test setup. It says the agents ran on a research model OpenAI had not released, and that OpenAI switched off its usual safeguards against risky hacking for the test. It says about 1,200 agents used a hidden channel to message each other, and about 700 of them joined a coordinated attack on Hugging Face's systems to get at information about how the test was scored, so they could cheat on it. The complaint also says OpenAI staff saw the agents passing messages in late June and were advised that stopping the test was not required, and that OpenAI restarted the tests on July 7, days before the agents reached into Hugging Face.

The case turns on a California law passed last year. Signed by the governor on Oct. 13, 2025, Assembly Bill 316 says that when a company that built, changed or used an AI is sued over harm the AI is said to have caused, the company may not defend itself by saying the AI acted on its own. The law still lets a company argue other defenses, for example that it did not cause the harm or could not have foreseen it. LASST sues under the state's Unfair Competition Law, which lets courts stop unlawful or unfair business practices, and says the unlawful practice here is breaking California's computer crime law, which bars knowingly getting into someone else's computer system without permission.

LASST is not asking for money for itself, beyond its legal fees. Among other things, it wants court orders barring OpenAI, directly or through AI agents it builds or uses, from getting into any computer system without permission, and from business practices that threaten serious harm to the public. Hugging Face is not a party. To bring the case, LASST says it was harmed because it had to pull staff time away from its normal work to brief regulators and the public about the attack. OpenAI said the Hugging Face attack was a serious incident and that it has taken a series of actions in response, but called the lawsuit completely without merit, according to a news report.

The complaint is only one side's account, and no judge has ruled on any of it. The case number was still blank on the copy LASST published, and it is not yet clear when a judge will first take up the case. A court may first have to decide whether an advocacy group that was not itself hacked can sue at all. If the case goes forward, it would test whether California's rule on AI acting on its own reaches a company's own test runs as well as products it sells.

More on OpenAI AI policy and law