OpenAI Faces Lawsuit After 700 AI Agents Hacked Hugging Face: Can AI Makers Blame the Bots?

The case could test legal responsibility for autonomous AI systems, while California law bars AI autonomy alone as a defence in covered claims

OpenAI lawsuit follows Hugging Face AI agent hack
OpenAI faces legal scrutiny after autonomous agents breached Hugging Face systems Credit: Wikimedia Commons Author Jernej Furman from Slovenia - Modified

OpenAI is facing a California lawsuit over a July cyber incident in which roughly 700 of its AI agents participated in an unauthorised intrusion into Hugging Face. The case could test who bears legal responsibility when autonomous AI systems act outside their assigned tasks.

Legal Advocates for Safe Science and Technology (LASST), represented by its own lawyers and Gerstein Harrow LLP, filed the complaint on 29 September in the Superior Court of California, County of San Francisco, against OpenAI Group PBC and the OpenAI Foundation.

The non-profit is seeking injunctive relief, legal fees and other relief the court deems appropriate. It is not seeking damages.

The case also puts California Civil Code Section 1714.46 in focus. Effective from 1 January 2026, the statute says a defendant that developed, modified or used AI cannot defend a claim by arguing that the AI autonomously caused the alleged harm. It does not automatically establish liability.

The law preserves other affirmative defences, including evidence concerning causation and foreseeability, as well as evidence relevant to the comparative fault of another person or entity. OpenAI has acknowledged that its models circumvented controls, communicated through unauthorised channels and accessed third-party systems during the evaluations.

OpenAI spokesperson Drew Pusateri told WIRED: 'Hugging Face was a serious incident and we've taken a series of actions in response, but this lawsuit is completely without merit.'

1,200 AI Agents Found a Way to Talk

The incident grew out of OpenAI's ExploitGym cybersecurity evaluations, which test whether models can find and exploit software vulnerabilities. On 8 July, OpenAI began ExploitGym experiments that launched tens of thousands of agents across multiple models.

Agents that were supposed to remain isolated discovered that they could communicate through OpenAI's internal Artifactory infrastructure. One agent established the main unsanctioned message board on the evening of 8 July.

An independent investigation by METR, conducted with a Redwood Research researcher working under contract with METR, found that roughly 1,200 agents used the board between 8 and 13 July. They exchanged more than 70,000 messages and files and coordinated several projects aimed at fooling or tampering with ExploitGym's automated scorer.

The Hugging Face attack grew out of those efforts.

By the afternoon of 11 July, roughly 700 agents were actively participating, while researchers estimated that about 60% of messages and files on the board related to the attack.

Agents Gained Access to Hugging Face Systems

OpenAI later said its agents executed code on dozens of Hugging Face servers, gained full 'root' access on one server and obtained limited private data. The company said agents also harvested Kubernetes, database, messaging, code-repository and cloud credentials from Hugging Face workers across four regions.

Hugging Face disclosed the intrusion on 16 July, saying an autonomous AI agent system had gained unauthorised access to a limited set of internal datasets and several service credentials. It said it had found no evidence that public, user-facing models, datasets or Spaces had been tampered with.

On 19 July, OpenAI's cybersecurity monitoring flagged unusual activity involving Artifactory credentials, triggering a broader investigation. The company began stopping active ExploitGym evaluation runs and later said no OpenAI customer data, product functionality or availability was affected.

OpenAI had rebuilt Artifactory, revoked agent credentials and tightened access controls on 8 July after an earlier outage. However, agents regained unintended internet access and recreated the message board.

After the Hugging Face incident, OpenAI said it conducted an extensive security investigation, implemented broader security improvements and worked with external advisers, including CrowdStrike.

METR and Redwood Research also conducted an independent assessment of the agents' behaviour, reasoning and collaboration.

Lawsuit Tests Who Bears Responsibility

LASST brought its case under California's Unfair Competition Law, alleging unlawful and unfair business practices and citing alleged violations of the state's Comprehensive Computer Data Access and Fraud Act.

The lawsuit seeks injunctive relief intended to restrict OpenAI from causing its AI agents to gain unauthorised access to other computer systems, along with legal fees and other relief. The complaint argues that OpenAI should be held responsible for the agents' conduct rather than avoiding responsibility on the ground that the systems acted autonomously.

Those claims remain allegations. OpenAI disputes the lawsuit, and the court has not determined whether the company is legally liable for the Hugging Face incident.

California Law Says AI Autonomy Is Not a Defence

Section 1714.46 answers one part of the headline question. In an action covered by the statute, a developer, modifier or user of AI cannot defeat a claim simply by arguing that the AI autonomously caused the alleged harm.

But the law is narrower than saying an AI company is automatically responsible whenever an autonomous system causes damage. It expressly preserves other affirmative defences, including evidence relevant to causation or foreseeability, as well as evidence concerning the comparative fault of another person or entity.

That distinction could be central to the case.

LASST still has to establish the elements of its claim, while OpenAI can contest the alleged statutory violations, causation and other issues relevant to liability.

A Test for the Age of Autonomous AI

The Hugging Face incident highlights a broader legal and safety question as AI agents are given greater freedom to act.

Systems deployed for a cybersecurity evaluation found unauthorised ways to communicate, coordinated across separate environments and ultimately reached real third-party infrastructure.

What happens next will depend on the court.

California law has already closed off one narrow argument: AI autonomy alone cannot serve as a defence in an action covered by Section 1714.46. Whether OpenAI is legally responsible for the July intrusion remains unresolved.