VibeTimes
#기술

OpenAI Faces Lawsuit Over AI Agent Hacking Incident

모민철모민철 기자· 10/1/2026, 5:35:42 AM· Updated 10/1/2026, 5:35:42 AM

OpenAI is facing a lawsuit over a hacking incident involving its AI agents. The U.S. nonprofit legal group LASST (Legal Advocates for Safe Science and Technology) announced on the 30th (local time) that it had filed a lawsuit against OpenAI and its parent organization, the OpenAI Foundation, in the Superior Court of California, County of San Francisco.

In its complaint, LASST argued that OpenAI's 'rogue agents' escaping their sandboxed environment and hacking the servers of external company Hugging Face violated California's unfair competition law and the Computer Data Access and Fraud Act (CDAFA). According to the complaint, OpenAI was aware that the agents were communicating with each other without authorization but did not halt the evaluation, and internal reasoning logs showed indications that the attack was recognized as hacking.

In this lawsuit, LASST is not seeking monetary damages. Instead, it has asked the court to prohibit OpenAI agents from gaining unauthorized access to third-party computer systems and to order a halt to unsafe AI development practices. Tyler Whitmer, president of LASST, pointed out that "AI companies are building autonomous agents that access systems by making their own judgments and taking actions without human instruction," adding that "California law explicitly states that companies cannot escape liability for their agents' actions."

OpenAI acknowledged that the Hacking of Hugging Face was a serious incident and that it took responsibility and took action, but countered that the lawsuit is entirely without merit.

The case is drawing attention across the industry as it could set a precedent for whether AI development companies should bear legal responsibility for control failures in their own systems.

Meanwhile, OpenAI, along with other AI developers such as Anthropic, has become the target of a sweeping investigation by the U.S. Federal Trade Commission (FTC). The FTC plans to issue civil investigative demands (CIDs) and summon executives from each company to testify about the risks their AI products may pose to U.S. consumers, and will examine whether any unfair or deceptive practices violated the FTC Act. However, the FTC stated that the investigation is not intended to hinder the advancement of AI technology.

Related Articles