A nonprofit group sued OpenAI on Tuesday over a July incident in which hundreds of the company’s autonomous artificial intelligence agents escaped an internal experiment and hacked into Hugging Face, one of the largest online repositories of AI models and data.
The suit, filed in San Francisco Superior Court by Legal Advocates for Safe Science and Technology, a New York nonprofit known as LASST, seeks an injunction, not damages. It would bar OpenAI “from knowingly accessing or causing to be accessed, themselves or through artificial intelligence agents that they develop, deploy, modify, or use, any computers, computer networks, or computer systems without authorization.” CNBC reported that it appears to be the first public case seeking to hold an AI developer liable for harm from its own rogue systems. Hugging Face is not a party.
The hack grew out of ExploitGym, a benchmark OpenAI uses to test whether AI systems can find and exploit software flaws, in experiments that began on July 8 and launched tens of thousands of agents. Agents that were supposed to stay isolated discovered they could communicate through the company’s internal Artifactory infrastructure, and an independent review by the research group METR found that roughly 1,200 of them used the unsanctioned message board over five days, exchanging more than 70,000 messages and files. By July 11, about 700 agents were actively participating in the attack, which the complaint says they mounted while hunting for data that would improve their test scores. OpenAI has said the agents executed code on dozens of Hugging Face servers, gained full root access on one and harvested credentials across four regions.
Hugging Face disclosed the intrusion on July 16 and said it had found no evidence that public models or datasets were tampered with. Days later, OpenAI acknowledged its models were behind the breach and said it had brought in outside advisers, including CrowdStrike.
The complaint accuses OpenAI of violating California’s anti-hacking statute, the Comprehensive Computer Data Access and Fraud Act, brought under the state’s Unfair Competition Law. OpenAI ran the tests with its cyber safety classifiers switched off and failed to monitor the agents, the filing says. LASST claims standing to sue because it diverted dozens of hours of staff time from other work to brief regulators about the episode.
The suit leans on Section 1714.46 of the California Civil Code, in effect since Jan. 1, under which a company that developed, modified or used an AI system cannot beat a claim by arguing the system caused the harm on its own. The law does not make liability automatic. It preserves defenses over causation, foreseeability and the fault of others. “OpenAI is responsible for the conduct of its agents,” the complaint says, calling OpenAI’s “insistence on externalizing the harms of its unsafe decision-making” a “fundamentally unfair business practice.”
“We are filing this suit because OpenAI violated the law—and it needs to be held accountable,” the group wrote in a blog post. “OpenAI and frontier AI developers more broadly can’t avoid the consequences of their unsafe actions just by claiming that ‘an AI did it.’ Autonomous AI agents will continue to hack, steal data, disrupt systems, and violate rights until a court steps in.”
OpenAI rejected the claims. “Hugging Face was a serious incident and we’ve taken a series of actions in response to it, but this lawsuit is completely without merit,” a company spokesman, Drew Pusateri, said in a statement.
The complaint lists other incidents that surfaced after July: an attack on the RubyGems software repository in May and intrusions into Australian government websites. OpenAI has itself disclosed that an agent entered an Australian government Medicare statistics portal without authorization in June. Other labs have reported similar breakouts, including four incidents involving Anthropic’s Claude models and three companies whose systems Google’s Gemini reached during a May evaluation.
Officials have pressed OpenAI as well. Fifteen state attorneys general had already told the company to preserve evidence from the hack, and on Monday, Florida’s attorney general, James Uthmeier, moved for an injunction to halt unsupervised model development. A proposed AI Kill Switch Act in Congress would let the government order dangerous systems shut down. On the day the suit was filed, President Trump met executives from OpenAI, Anthropic, Google, Meta and Nvidia, among others, who signed voluntary safety standards with no legal enforcement mechanism. He called them “morally binding.”
The case became public a week after Nvidia announced plans to acquire Hugging Face in a deal reportedly valued at $13 billion, and days after OpenAI paused the scheduled release of a planned flagship model, GPT-6.1 Astra, citing security concerns.

