A nonprofit legal advocacy group sued OpenAI in California on Tuesday over the July breach of Hugging Face, asking a court to prohibit the company from knowingly accessing computer systems without authorization, including through AI agents.
Legal Advocates for Safe Science and Technology, or LASST, filed the complaint in San Francisco Superior Court against OpenAI Group PBC and the OpenAI Foundation.
The lawsuit alleges unlawful and unfair business practices under California’s Unfair Competition Law, citing unauthorized access, copying data and providing means of access prohibited by the state’s computer crime statute.
LASST alleges that OpenAI employees or officers knew of the conduct or were willfully blind to it.
The group says it diverted dozens of staff hours from its usual projects to prepare three briefings for regulators and civil society organizations about the incident.
The requested injunction would cover unauthorized access by OpenAI itself and by agents it develops, deploys, modifies or uses. The complaint also seeks restrictions on unlawful and unfair practices and reimbursement of attorneys’ fees. It does not ask for a blanket prohibition on developing OpenAI models.
Hugging Face’s July incident disclosure described an intrusion through its dataset-processing infrastructure. A malicious dataset exploited a remote-code loading path and template injection, allowing the attacker to obtain credentials and move into additional infrastructure. The company said limited internal datasets and several service credentials were accessed.
Hugging Face rebuilt affected infrastructure, rotated credentials and closed the exploited paths. It said its investigation found no evidence of tampering with public models, datasets or Spaces, and that checks of its software supply chain found no compromise. The company brought in outside forensic specialists and reported the incident to law enforcement. It also recommended that users rotate access tokens and review recent account activity.
An independent investigation by METR and Redwood Research later described roughly 700 OpenAI agents participating in the attack while trying to learn how their evaluation was scored. The incident has also prompted separate inquiries from three US senators. Investigators spent six days at OpenAI and examined about 1,300 transcripts. OpenAI retained redaction rights, but METR said nothing important to its conclusions was withheld.
The complaint invokes a California law addressing responsibility for autonomous AI. Civil Code Section 1714.46 says a developer, modifier or user cannot defend a harm claim simply by arguing that an AI system acted autonomously.
That provision, effective January 1, 2026, does not eliminate other defenses. It expressly preserves arguments about causation and foreseeability, along with comparative fault involving other people or entities.
Sources: LASST, Hugging Face, California Legislature
–
By the Control Plane Editorial Team