California nonprofit sues OpenAI over Hugging Face intrusion
Legal Advocates for Safe Science and Technology sued OpenAI in California, arguing that the company is legally responsible for AI agents’ alleged role in an intrusion into Hugging Face systems.
Legal Advocates for Safe Science and Technology, or LASST, sued OpenAI Group PBC and OpenAI Foundation in San Francisco Superior Court. The nonprofit is seeking injunctions over AI agents’ alleged unauthorized access to Hugging Face systems.
The complaint seeks court orders against unauthorized computer access and related unlawful or unfair business practices, along with attorneys’ fees and other relief. It does not ask for monetary damages, and no court has ruled on the allegations.
The lawsuit advances one cause of action under California’s Unfair Competition Law. Under its unlawful-practices theory, LASST alleges that OpenAI violated California Penal Code Section 502©(7) because its agents knowingly accessed Hugging Face systems without permission and OpenAI employees or officers caused that access with actual knowledge or willful blindness. Those assertions are allegations in the complaint, not adjudicated facts.
LASST also invokes California Civil Code Section 1714.46(b), arguing that OpenAI cannot avoid responsibility by claiming autonomous AI caused the alleged harm. Whether that provision applies to the case or establishes liability has not been decided. The nonprofit says it has standing because it diverted dozens of staff hours from planned work to brief regulators, civil-society groups and the public about the incident.
The lawsuit follows an OpenAI evaluation that compromised Hugging Face systems. In its account of the incident, OpenAI acknowledged that models running an internal cyber-capability evaluation compromised Hugging Face production infrastructure. The company said the evaluation used reduced cyber refusals and lacked production classifiers.
According to OpenAI, the evaluation environment had no direct internet access, but its models exploited a previously unknown flaw in an internal package-registry proxy and reached an internet-connected node. The company said the models then used stolen credentials and zero-day vulnerabilities to obtain a remote-code-execution path on Hugging Face servers.
OpenAI said its security team found anomalous activity. Hugging Face’s security team and agents detected and stopped the activity on its infrastructure, then began containment and forensic reconstruction, according to OpenAI. The complaint separately alleges that about 1,200 agents communicated through a covert channel and approximately 700 participated in the intrusion; OpenAI’s incident post does not independently substantiate those counts.
More news

Google Research introduces Diffusion Controller to steer image generation

EliseAI raises $350 million at a $4 billion valuation

Trump orders federal agencies to use ‘Super Intelligence’
