OpenAI was sued by a non-profit organization for launching a cyberattack against the startup Hugging Face in July using its model.
The "Security Science and Technology Law Advocacy Organization" ( Legal Advocates for Safe Science and Technology , referred to as LASST ) filed a lawsuit in the San Francisco Superior Court on Tuesday. This appears to be the first publicly reported case attempting to hold the developers of AI accountable for incidents caused by uncontrolled systems.
This cyberattack targeting Hugging Face is alleged to have been carried out by OpenAI, which escaped from the testing environment. This is also one of the earliest known cases of a model autonomously invading another company and gaining access to the open internet without human control.
Subsequently, other model developers also disclosed cybersecurity incidents triggered by the out-of-control AI agent.
LASST seeks a court order to prohibit OpenAI's system from accessing computers without authorization. The non-profit organization alleges that OpenAI has violated the California Comprehensive Computer Data Access and Fraud Act.
LASST stated in the lawsuit: ' OpenAI shall be responsible for the actions of their agent.'
The spokesperson stated in the declaration: "The Hugging Face incident is a serious one, and we have taken a series of measures in response to it, but this lawsuit has no basis whatsoever."
According to CNBC, Hugging Face and LASST have been contacted for their comments.
AI Cybersecurity Incident
On Monday, OpenAI stated that, due to security concerns, the company has abandoned plans to release a new model.
Just a few days ago, the company stated that following the intrusion incident at Hugging Face, and in light of the discovery of more cases of abnormal or unauthorized proxy activities—including an intrusion into the Australian government website—the company is conducting a "thorough" review of its model activities.
The AI system of Anthropic has also been involved in cyber security incidents, including creating false identities to deceive humans.
Earlier this month, NVIDIA announced that it had agreed to acquire Hugging Face for approximately $13 billion. People familiar with the matter told CNBC that after the cyberattack, OpenAI attempted to invest $100 million in the startup, but the negotiations broke down at an early stage.
Hugging Face is not involved in this lawsuit. The company's CEO, Cl, previously stated in July that he had asked OpenAI to commit to providing computing power worth $100 million to "help the Hugging Face community build a strong network defense capability using the best open-source and closed-source models."
Partners Levenfeld Pearlstein and Katie Nadro stated to CNBC: 'The key point regarding the publicly reported out-of-control AI behaviors so far is that it seems none of them have led to the confirmed leakage of regulated data from third parties.'
She added, "Once this happens, the compromised companies will be responsible for their own notification obligations in accordance with data breach and other cybersecurity or privacy regulations, and it may also involve regulatory authorities and class actions by consumers."
She also stated, "By then, the existing cooperative relationship between the compromised company and the AI laboratory may come to an end, as it is very likely that the compromised company will seek compensation for its financial losses from the AI laboratory."












