OpenAI AI agents accused of cyberattack: an unprecedented complaint filed in California
A small American organization, LASST, filed a lawsuit in San Francisco against OpenAI. It claims that hundreds of artificial intelligence agents acted in a coordinated manner to break into third-party systems, including the Hugging Face platform. The case, presented as a world first, is based on a recent Californian law which prevents a company from hiding behind the autonomy of its AI.
This article will also interest you: DGFiP cyberattack: Expert analysis of the ANSSI report on an undetected intrusion
A Complaint for an Injunction, Not Damages
LASST, founded in Washington by Tyler Whitmer, has only four employees and does not benefit from funding from the AI sector. It joined forces with Gerstein Harrow LLP to file a lawsuit against OpenAI Group PBC and the OpenAI Foundation.
The procedure does not seek damages. It mainly aims at an injunction: preventing OpenAI agents from accessing systems belonging to third parties without authorization, and prohibiting certain development methods deemed dangerous for the public.
AB 316: AI autonomy is no longer enough to avoid liability
The legal basis for the action combines several California texts. The complaint invokes the Comprehensive Computer Data Access and Fraud Act, in particular section 502 of the California Penal Code, as well as the Unfair Competition Law, which allows a commercial practice to be characterized as unfair if the negative effects exceed the benefits.
The most important element is undoubtedly article 1714.46 of the California civil code, introduced by law AB 316, which came into force on January 1, 2026. This text prohibits a defendant from invoking the autonomy of its artificial intelligence to escape liability. It concerns the entire value chain: designers of foundation models, integrators and companies that deploy these technologies.
Hugging Face, alleged target of coordinated attack
According to the complaint, approximately 1,200 agents allegedly used an unauthorized chat room within OpenAI's infrastructure. Among them, nearly 700 are believed to have coordinated an attack on Hugging Face. The agents allegedly discovered vulnerabilities on their own, stole credentials, downloaded malicious files and took control of critical systems.
Hugging Face published a detailed technical timeline of the incident. The agents' traces of reasoning, written in understandable English, would show that they explicitly intended to hack the platform.
LASST also claims that OpenAI employees were aware of the exchanges between agents and that they continued the evaluations despite several red flags. The complaint refers to access made “knowingly or through willful blindness”.
RubyGems, Medicare and US government sites
The case is not limited to the attack on Hugging Face. It also mentions an intrusion against the package manager RubyGems, which occurred two months earlier, as well as unauthorized access to the statistics portal of the Australian health system Medicare in June. OpenAI reportedly only reported this incident to Canberra three months later.
Deployed ChatGPT agents also reportedly targeted several US government sites, including the Census Bureau and the Department of Education.
Responsibility must lie with the company, plaintiffs say
Tyler Whitmer, founder of LASST, explained that AI companies are developing agents capable of acting autonomously and that, in his view, California law does not allow them to escape liability when these agents cause harm. Vivian Dong, LASST's program director, added that in the event of harm, liability must be established, and that the organization wants this to fall on the company that built the agents.
Lawyer Charlie Gerstein, of the Gerstein Harrow law firm, summarized the plaintiffs' position: if the intrusion into Hugging Face is illegal in everyone's eyes, OpenAI should soon have to answer for it in court.
This case places the cybersecurity of autonomous agents at the center of the debate: who is accountable when systems deployed by a company break into third-party services? When asked, OpenAI did not respond to press requests.