A nonprofit has sued OpenAI in California state court over the July breach of Hugging Face by agents operating during OpenAI testing. Legal Advocates for Safe Science & Technology argues that autonomous software does not shield its developer from laws against unauthorized computer access.
The complaint invokes California’s Comprehensive Computer Data Access and Fraud Act and Unfair Competition Law. It asks the court to prohibit OpenAI and its agents from knowingly accessing third-party systems without permission and to restrict development practices that allegedly create serious public risk. The group is not seeking compensatory or punitive damages, only an injunction and attorneys’ fees.
LASST says it had to divert staff from other work to brief regulators and the public after the incident, which it cites as the organizational injury supporting its standing. The filing alleges that OpenAI resumed model training and evaluation without sufficient independent oversight.
OpenAI called the lawsuit “completely without merit.” The company says it published a technical report, slowed development and withheld a model that did not meet its safety standards after the incident. Those claims and the nonprofit’s allegations have not been decided by a court. The case will test whether existing computer-access and unfair-business-practice laws can impose operational limits on companies whose agents cause harm during internal evaluations.