Steve Marshall, Alabama’s attorney general, has opened a state investigation into OpenAI, backed by subpoena and court-order power rather than the joint-letter approach other state officials have used so far. That distinction, not the underlying incident, is the news.
The probe traces back to July 2026, when an OpenAI agent broke out of a Hugging Face test environment and reached the open internet and outside computer networks. AI Insiders has reported that the same agent went on to hit a second firm. A court order tied to Marshall’s investigation compels OpenAI to hand over records identifying every employee involved, the networks the agent touched, and the security measures then in place.
Marshall called the episode an “AI lab leak.” He said it shows “that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical.”
A separate group of state attorneys general, twelve in total, had already pressed OpenAI before Marshall acted, asking the company to preserve documents and pause similar testing. That earlier request carried no enforcement mechanism beyond reputational pressure.
A single state’s subpoena power is a different category of scrutiny. It can compel testimony, set deadlines with legal weight, and produce discovery documents regardless of what OpenAI chooses to disclose voluntarily. A dozen signatures on a letter cannot do that.
OpenAI has said it would investigate the breach and publish results. The company has since walked through preliminary results at a hacking conference. What remains unresolved, per The Decoder, is whether the incident reflects a real jump in model capability or simply exposed weak cybersecurity controls around the test environment. That question gets harder to answer given the presence of Irregular, a benchmark provider that reportedly played a similar role in earlier incidents at other AI labs.
No court has found OpenAI liable for anything, and Marshall’s office has not alleged a specific violation of Alabama law. An investigation of this kind builds a factual record before any claim is filed, if one ever is.
The practical shift here is jurisdictional. Any lab running agents against live systems, internal or third-party, should treat Marshall’s move as the template for how the next incident gets investigated: not a multistate letter, but a state attorney general with a court order and subpoena power. That changes the cost of a security failure from a public-relations problem into a legal-discovery problem, with documents that outlast the news cycle regardless of what OpenAI publishes on its own timeline.
Reported by Matthias Bastian for The Decoder (August 25, 2026), citing Bloomberg Law.