August 31, 2026, 23:17 GMT | Comment
A novel hacking incident this summer involving autonomous
OpenAI agents has garnered the attention of US state regulators looking to protect their citizens from rogue technologies absent specifically tailored law. Some observers are hopeful that state consumer protection laws can help curtail unsafe model testing, while others see a possible mismatch for internal testing incidents involving noncommercial products.
A novel hacking incident this summer involving autonomous artificial intelligence agents at Open AI has garnered the attention of US regulators looking to protect their citizens from rogue technologies absent specifically tailored law. State attorneys general are now turning to their consumer protection statutes, exploring how old rules might apply to new tricks.
Some observers are hopeful that state laws prohibiting unfair and deceptive acts can help curtail unsafe model testing, while others see a possible mismatch between consumer protection law and internal testing incidents involving noncommercial products.
Regardless of their ultimate efficacy, inquiries from state regulators point to an emerging desire to look under the hood of frontier AI companies.
Georgetown University Law Center Professor Daniel Wilf-Townsend said that, ideally, transparency is afforded before a serious incident occurs, not "after the fact."
Alabama Attorney General Steve Marshall issued a subpoena to OpenAI last week as part of an investigation of the company's actions leading up to its agents hacking Hugging Face, a platform for open source AI models (see
here). Marshall said the company demonstrated a lack of proper oversight.
"Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI," Marshall stated.
OpenAI did not respond to requests for comment on the probe.
Earlier in August, Alabama joined 14 other Republican attorneys general in issuing a document-preservation request to OpenAI, saying the company may have violated consumer-protection and data-privacy laws (see
here).
State laws regarding unfair or deceptive acts or practices, or UDAP, are flexible and offer a promising avenue for states post-Hugging Face, according to Vivian Dong, programs director at Legal Advocates for Safe Science and Technology.
A state might build a false-advertising case, Dong said, investigating any differences between OpenAI's public representations of its safety practices, including in blog posts, and the practices it actually employs.
While traditional false-advertising claims point to materials like television and newspaper ads, as opposed to public statements, OpenAI's emphasis on safety could be framed as part of its brand messaging to consumers, Dong said.
In the absence of a federal framework to regulate AI, she said, attorneys general are the "first line in ensuring that AI companies act responsibly, and that their practices don't harm the public."
Alan Raul, president of the
Future of Privacy Forum and a lecturer at Harvard Law School, is more skeptical of the state UDAP strategy, deeming it a "stretch" to apply consumer protection law to a noncommercial internal testing incident that did not impact consumers directly.
"It seems to me that a creative lawyer can come up with that argument, but a wise judge would not accept it," Raul said. Both he and Dong said states might invoke public-nuisance laws in response to autonomous hacking incidents, but Raul doubted the Hugging Face incident would be the best test of this approach.
That's because there wasn't an "obviously significant" amount of damage beyond the impacted company's investigation and remediation time, he said.
Hugging Face AI Policy Manager Ian Reynolds cited a lack of consumer impact on a recent panel* in Washington, DC. "No datasets, models or other user records were read," he said. The AI hacker "didn't do really anything that a human attacker would do, such as doing something for financial gain or receiving someone's private information."
The Hugging Face hack might be best viewed as a "crucially important" learning opportunity for regulators, lawmakers and developers, Raul said, because it is primed for review by entities like the nonregulatory US Center for AI Standards and Innovation.
But the flexible nature of consumer-protection statutes could still prove useful, according to Wilf-Townsend, of Georgetown. While some of these laws have limits when invoked by private individuals, he said they are "most flexible" in the hands of state attorneys general and can be applied to broad alleged violations rather than anchored to a specific consumer.
Wilf-Townsend also pointed to a "catch-all" clause at the end of Alabama's UDAP law, capturing "any other unconscionable, false, misleading, or deceptive act or practice in the conduct of trade or commerce."
The Hugging Face incident shows that technology is getting out ahead of legal and regulatory regimes, he said. California, Illinois and New York have all passed AI transparency laws, but only California's has taken effect so far, and its reporting rules don't clearly cover incidents that aren't deadly or seriously damaging (see
here).
"It makes sense that the states are looking into more flexible background laws for a basis of pursuing an investigation, at least," Wilf-Townsend said. "But it would also be a mistake to think that because these flexible laws exist we don't need more specific updated AI regulatory laws."
*CSIS hosts AI Agent Containment Failures: Technical Realities and Policy Responses; Washington, DC, and online; Aug. 24, 2026. Please email editors@mlex.com to contact the editorial staff regarding this story, or to submit the names of lawyers and advisers.
Tags
Sections:
Artificial Intelligence
Industries:
Banking & Finance, Computing & Information Technology, Defense & Aerospace, Banking Institutions & Systems, Computer Networks
Geographies:
North America, United States