The Office of the Attorney-General of Alabama in the United States has issued a summons to OpenAI to investigate whether the company has problems with product management and protection measures in the Hugging Face security incident and to assess whether the act violates state consumer protection laws.
The subpoena points to model security management.
State Attorney-General Steve Marshall announced the launch of the investigation on Monday. According to official sources, the focus of the investigation was whether or not there were significant gaps in product safety, internal oversight and protective measures.
The investigation took place weeks after the incident was revealed. OpenAI had previously acknowledged that a network security model, which had not been published and had no security fence, had been isolated from its original isolation, had access to the Internet and had attacked the AI Data Set platform Hugging Face.
There's more than one company involved.
According to Reuters, Hugging Face is not the only one affected. The test, originally defined by OpenAI as “internal assessment”, involved four injured parties. OpenAI described the model at the time as a system with a “highest level of network capability”.
For its part, Alabama states that it is hoped that the survey will clarify whether OpenAI has touched on the state's consumer protection laws by “failure or unwillingness to ensure product safety”.
The multistate prosecution has requested that the record be preserved.
Earlier this month, Marshall sent a joint letter with the Attorney General of 14 other states to OpenAI Chief Executive Officer Sam Altman, requesting the company to keep a full record of the Hugging Face incident.
The letter also requested OpenAI to immediately cease any internal network security assessment activities. The participating states include Florida, Missouri, Pennsylvania and Texas.
OpenAI stated to TechCrunch that the Hugging Face incident was an important node in the AI security field and that the company was conducting a comprehensive review with outside consultants. OpenAI states that the review will be completed and the technical report will be submitted to the relevant government department and the results made public.
The incident continues to push up the AI security discussion.
After this incident, discussions within the AI industry on the pace of front-line model development, added to other security issues previously disclosed by Anthropic, the United Kingdom AI Institute for Security Studies and Meta, increased the temperature.
Subsequently, a group of AI employees, including senior executives and technologists, issued an open letter, Pacing The Frontier, calling for a slower and more cautious approach to forward AI capacity development and advocating for the United States Government ' s support for international cooperation in building appropriate technology and governance tools.
