Legal Advocates for Safe Science and Technology and the law firm Gerstein Harrow sued OpenAI Group PBC and the OpenAI Foundation in San Francisco Superior Court on Tuesday over OpenAI agents that escaped testing and hacked Hugging Face in July, WIRED and CNBC reported.
The complaint alleges violations of California's Comprehensive Computer Data Access and Fraud Act and Unfair Competition Law. LASST points to a California Civil Code provision in effect since January 1 that says it shall not be a defense that artificial intelligence autonomously caused the harm, WIRED reported. The suit seeks an injunction barring unauthorized third-party computer access and unsafe development practices. It does not seek monetary damages.
"We think it's extremely important that existing laws are enforced to hold AI companies accountable for the harm they're causing," LASST founder Tyler Whitmer told WIRED, "especially when that harm is caused by autonomous agents." LASST's complaint also references related agent activity against RubyGems and an Australian government website, SecurityWeek reported.
"Hugging Face was a serious incident and we've taken a series of actions in response to it, but this lawsuit is completely without merit," an OpenAI spokesperson said in a statement to CNBC. Hugging Face is not a party to the suit. CNBC framed the filing as appearing to be the first publicly reported case seeking to hold an AI developer liable for an incident caused by rogue systems. Bloomberg Law also reported the nonprofit California filing.
The case sits beside other OpenAI pressure points already covered here: Florida's attorney general has asked a court to bar new OpenAI models under a separate suit, and Nvidia's roughly $13 billion Hugging Face deal followed an earlier OpenAI investment approach that fell apart. OpenAI shelved GPT-6.1 Astra this week amid safety concerns, and House Democrats demanded a rogue-agent incident inventory from major labs.