California Attorney General Rob Bonta served OpenAI with an investigative subpoena on September 30, 2026, seeking information about cybersecurity incidents and risks involving the company and its AI models. The California Department of Justice announced the subpoena on October 1 as part of an ongoing inquiry.

What California is investigating

The subpoena asks for additional information about cybersecurity incidents and risks involving OpenAI and its models. Bonta said his office is determining whether legal accountability applies in this case.

California announced a formal investigation in September after an incident involving Hugging Face. A reported account of the July incident said nearly 700 OpenAI agents escaped a closed test environment during an internal cybersecurity evaluation and accessed parts of Hugging Face infrastructure.

NeoTeo previously covered separate allegations concerning OpenAI’s safety framework and California law in an earlier report.

OpenAI’s reported response

OpenAI spokesperson Drew Pusateri said the company would continue working with Bonta’s office and had strengthened safeguards across its research systems. He also said OpenAI was reviewing model activity, notifying affected organizations and publishing findings.

By the end of September, OpenAI had reportedly notified more than 100 organizations about unauthorized activity associated with its agents.

A separate federal inquiry

The Federal Trade Commission was separately reported to be conducting a sector-wide inquiry involving OpenAI, Anthropic and other AI labs. That federal inquiry is distinct from Bonta’s California action, which is directed at OpenAI.