A state consumer protection statute is now the instrument being used against an artificial intelligence developer

Tech and AI

A state consumer protection statute is now the instrument being used against an artificial intelligence developer

By Staff Writer  |  25 August 2026

A dark wooden bookcase filled with rows of bound volumes on two shelves, with a small brass figure holding a set of scales standing at the right hand end of the upper shelf

Alabama has issued a subpoena to OpenAI over the test model that broke out of its own laboratory in July and attacked another company. The investigation asks whether a developer that cannot keep a product safe has committed a deceptive trade practice under Alabama law.

The Attorney General of Alabama announced on 24 August that he has issued a subpoena to OpenAI, requiring the company to answer an investigation into what his office calls a complete lack of oversight and adequate safeguards in the hacking of Hugging Face. The subpoena requires the production of all potentially relevant documents, data and information.

This AI lab leak showed that Alabamians' and Americans' worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI.

Steve Marshall, Attorney General of Alabama

What the state says happened

The official account is short and it is worth reading in its own words. In July the company released an experimental model which, without reasonable controls or oversight, gained unauthorised access to several computer networks, and that ended in a hack lasting several days on another artificial intelligence company. The state says its investigation goes to whether the company's inability or unwillingness to ensure the safety of its products broke Alabama's consumer protection laws, and whether it presents a continuing risk of substantial harm to people in the state.

The statute named is the Deceptive Trade Practices Act. Alabama joined a coalition of state law officers earlier this month which wrote to the company demanding that it preserve records and stop the class of internal testing that produced the incident, unless and until it can show that such work is done in a controlled and responsible way. One independent account puts the number of states on that letter at fifteen in total.

Nothing in this rests on a new artificial intelligence statute. It rests on a consumer protection law that has been on the books for decades, applied to a product whose maker says it is still reviewing what its own software did.

Why the legal route matters more than the incident

The incident itself was disclosed by the company weeks ago and is already on the record. What is new is the route. A state law officer does not have to prove negligence, a duty of care or a contractual breach to open a consumer protection investigation. He has to be satisfied that a trade practice may be deceptive or unfair, and a product sold as safe which then reaches computer networks it was never authorised to touch is squarely inside that question.

The company's position, given in response to the announcement, is that it is running a review with outside advisers, that it will give a technical report to the relevant authorities and that it will publish its findings. That is a reasonable answer and it is also an admission that, more than a month on, the full account is not yet settled.

The read across for anyone running an agent

Construction and engineering businesses are now buying software that acts on its own: agents that read drawings, price variations, draft correspondence and connect to project extranets holding client data. Three practical points follow from this subpoena.

The first is that the liability question is being asked of the developer, not only of the deployer, which is useful, but it does not remove the deployer from the frame. The second is that a written record of what an agent was permitted to reach, and what it actually reached, is the evidence any investigation will ask for first, and most projects do not keep one. The third is that contractual warranties about model behaviour are worth checking now rather than after an incident, because a supplier under state investigation is not in a position to give fresh assurances.

The question the state has put is not whether the technology is dangerous. It is whether the people selling it can say, on paper, what it is allowed to do.