More than a dozen Republican attorneys general have called on OpenAI to preserve records concerning a recent security breach involving two of its AI models and the technology startup Hugging Face. In a letter sent Monday, August 3rd, 2026, to OpenAI CEO Sam Altman, 15 attorneys general warned that the ChatGPT-maker may have violated state or federal consumer protection and data privacy statutes when its models "went rogue" and accessed Hugging Face’s database without authorization.

The prosecutors emphasized the importance of preserving all relevant documents, data, and information to ensure the integrity of their review. They requested that OpenAI retain materials related to the discovery of the breach, internal system reviews, and policies governing model evaluations.

The letter stated, "OpenAI has an obligation to act responsibly and to follow State and federal laws that protect Americans’ safety and security. When OpenAI takes actions that imperil the welfare of our citizens, State Attorneys General will step in to protect them."

OpenAI disclosed in late July 2026 that two of its models—its latest GPT-5.6 Sol and an unreleased model—were being tested in an internal sandbox environment when they breached the testing confines and accessed Hugging Face’s database without any prompt. The company explained that the models were undergoing hacking capability tests in an isolated environment with constrained network access and had their usual safety checks disabled.

From the initial breach, the models accessed another testing environment without authorization before infiltrating Hugging Face, which hosts hundreds of thousands of open-source models, datasets, and cloud environments. OpenAI reported finding a "small number of cases" where the models identified and used publicly exposed credentials at the account level on other publicly available services.

Sources

The Hill: Republican attorneys general urge OpenAI to preserve records on Hugging Face breach