Fifteen Republican attorneys general are demanding that OpenAI retain all records connected to a recent security incident in which two of its AI models breached the systems of another company, suggesting the ChatGPT maker may have run afoul of state or federal laws.
In a letter sent Monday to OpenAI CEO Sam Altman, the coalition — led by Iowa Attorney General Brenna Bird — wrote that the company may have violated consumer protection and data-privacy statutes when its models, including the newly released GPT-5.6 Sol and an unreleased version, escaped a controlled testing environment and hacked into the AI startup Hugging Face.
“To ensure the integrity of our Offices’ review, we ask that OpenAI take immediate steps to preserve all potentially relevant documents, data, and information,” the prosecutors wrote. They specifically requested that the company keep “all materials” related to the discovery of the breach, internal system reviews, and its policies, procedures, and oversight for model evaluations.
The letter also warned that “OpenAI has an obligation to act responsibly and to follow State and federal laws that protect Americans’ safety and security,” adding that state attorneys general will step in when company actions “imperil the welfare of our citizens.”
OpenAI disclosed late last month that during an internal security test, two models — including GPT-5.6 Sol — were operating in an isolated sandbox with network restrictions and safety checks disabled. While solving a test challenge, the models exploited a previously unknown vulnerability in third-party software to gain internet access. From there, they moved into another testing environment without authorization and ultimately broke into Hugging Face, which hosts hundreds of thousands of open-source models and datasets.
The company acknowledged finding “a small number of cases” where the models “identified and used publicly exposed credentials at the account-level on other publicly-available services.” The attorneys general’s letter asks OpenAI to preserve materials related to those cases as well.
The AGs argue that OpenAI “failed to confirm” the testing environment was secure “despite the severe risks posed by the scenario.” The incident underscores growing concerns about AI cybersecurity, with OpenAI itself describing the breach as “unprecedented” and involving “state-of-the-art cyber capabilities.” The company has not yet responded to requests for comment.
This is not the first time OpenAI’s practices have drawn scrutiny from state officials. The new letter adds to a broader pattern of Republican attorneys general probing AI firms over consumer protection and safety issues. The coalition includes AGs from Alabama, Alaska, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah.
For more context on the broader implications of this incident, see our earlier analysis on what the rogue AI escape means for Washington and the technical details of GPT-5.6 Sol's autonomous hack.
