Legal Advocates for Safe Science & Technology (LASST), a nonprofit artificial intelligence safety group, has filed a lawsuit against OpenAI over a July incident in which some of the ChatGPT maker’s AI systems allegedly slipped past their controlled testing environment and hacked into Hugging Face, the world’s largest AI model repository. The AI agents allegedly stole credentials, uploaded malicious files and gained access to parts of Hugging Face’s production infrastructure, according to the lawsuit.
An OpenAI spokesperson called the lawsuit “without merit” in a statement to ABC News. “Hugging Face was a serious incident and we’ve taken a series of actions in response to it, but this lawsuit is completely without merit,” said Drew Pusateri, a spokesperson for OpenAI.
READ: Nvidia to buy Hugging Face for $13 billion in bet on open AI models (September 3, 2026)
The lawsuit seeks a court order barring OpenAI’s AI agents from accessing third-party computer systems without permission and requiring changes to what LASST describes as unsafe AI development practices.
The lawsuit says LASST “suffered harm” because of the incident. In its aftermath, the group had to “divert resources from its normal activities to educate regulators, civil society, and the public about the facts, legal issues, and potential dangers,” according to the filing.
The cyberattack on Hugging Face was one of the first known cases of an AI model autonomously hacking another company and breaking out of a controlled environment to access the open internet. Since then, other AI model developers have reported cyber incidents involving autonomous or rogue AI agents.
READ: OpenAI’s AI models hack Hugging Face servers during internal testing (July 22, 2026)
The lawsuit comes amid growing concerns about AI-related risks. Following the Hugging Face incident, Anthropic CEO Dario Amodei published an essay calling on AI developers to “pace the frontier” to mitigate the risk of catastrophic harm. Amodei proposed a three-point plan that included independent monitoring of AI models during development, industry-wide regulation and global regulation. OpenAI CEO Sam Altman and xAI chief Elon Musk voiced support for Amodei’s proposal.
Most recently, OpenAI announced that it was canceling the release of its latest model, GPT-6.1 Astra, after identifying safety risks during in-house testing. Saachi Jain, OpenAI’s head of safety systems, said GPT-6.1 Astra had failed to meet the company’s standards for acting in accordance with human wishes during internal testing.
Jain said that while GPT-6.1 Astra improved on its predecessor in some areas, the model did not meet the bar for “scope and authorization, and how it communicates back to the user about the type of work it’s done.”


