Wednesday, October 7, 2026
English edition

Development

"An AI did it" is no defense, says nonprofit suing OpenAI over Hugging Face hack

September 30, 2026 Development Source: Ars Technica

"An AI did it" is no defense, says nonprofit suing OpenAI over Hugging Face hack

Share this article

LASST said OpenAI’s voluntary response hasn’t been good enough and that the firm should be subject to court-imposed restrictions. “A business practice that exposes third parties and the public to uncontrolled, self-directed intrusions by systems that OpenAI admits it cannot fully predict or contain is unfair under any weighing of its utility against its consequences,” the group said. LASST’s lawsuit said OpenAI quickly resumed training and evaluations of AI systems after the Hugging Face hack and other security incidents. “OpenAI will continue to train and evaluate advanced models, without proper oversight, in sandboxes that are vulnerable to exploitation by those models,” the lawsuit said. A New York Times report yesterday said OpenAI executives ignored employees who warned months before the Hugging Face hack that OpenAI’s newest models weren’t being appropriately monitored. “In response, OpenAI executives told the employees that the tests needed to move forward as quickly as possible to release the AI models on time,” the NYT reported. “No additional security protocols were instituted, said the workers, who were not authorized to speak publicly on sensitive matters.” After the Hugging Face hack, LASST staffers set aside their normal workloads “to design, coordinate, and participate in a briefing regarding this incident for regulators,” and have since responded to more briefing requests that required additional work. LASST staff put dozens of work hours into responding to OpenAI’s unsafe development practices, the lawsuit said. “Despite the impact on LASST’s other programs, LASST nevertheless devoted its resources towards attempting to counteract OpenAI’s illegal conduct… If LASST prevails in this litigation, it will no longer need to divert its resources to combat the unlawful and unfair business practices employed by OpenAI concerning its AI agents hacking third parties during internal evaluations,” the lawsuit said. The lawsuit said the requested injunction should forbid OpenAI “from knowingly accessing or causing to be accessed, themselves or through artificial intelligence agents that they develop, deploy, modify, or use, any computers, computer networks, or computer systems without authorization,” and “from knowingly employing an unfair business practice that threatens serious harm on the public.” US lawmakers from both major parties have demanded answers from OpenAI, and a proposed “AI Kill Switch Act” would let US government officials order the shutdown of dangerous AI systems. LASST said new regulations are needed to protect the public from AI risks but said California’s existing law makes it possible to rein in AI companies “without waiting for new regulation to catch up to the harms happening to businesses and consumers now.” “We are filing this suit because OpenAI violated the law—and it needs to be held accountable,” the group said. “OpenAI and frontier AI developers more broadly can’t avoid the consequences of their unsafe actions just by claiming that ‘an AI did it.’ Autonomous AI agents will continue to hack, steal data, disrupt systems, and violate rights until a court steps in.”