California Issued Subpoena to OpenAI Over Cybersecurity

The state justice department is investigating potential cybersecurity risks associated with artificial intelligence models.

Updated on Oct. 2, 2026 in Artificial Intelligence

Isometric editorial illustration featuring a monolithic architectural structure paired with an abstract geometric crystalline volume, representing a state-level regulatory investigation into artificial intelligence cybersecurity.
The California Department of Justice has issued an investigative subpoena to OpenAI as part of a formal inquiry into the cybersecurity risks posed by artificial intelligence models. AI Illustration. Upload story photo >

Live Poll

Should government authorities impose stricter cybersecurity and safety regulations on AI development companies?

California Attorney General Rob Bonta has served an investigative subpoena on OpenAI as part of a formal probe by the California Department of Justice. The investigation focuses on cybersecurity incidents and potential risks posed by the company's artificial intelligence models.

Why it matters

The investigation seeks to determine if AI developers are failing to ensure their models do not inadvertently facilitate cyberattacks. This move underscores the state's broader commitment to ensuring that AI systems remain safe for all users, including children and teens.

The Attorney General has contacted 12 major AI companies as part of the ongoing effort to monitor industry compliance. This initiative includes a specific investigation into the Hugging Face incident.

The players

Rob Bonta

Rob Bonta serves as the Attorney General of California and is responsible for enforcing state laws and protecting residents from digital threats.

OpenAI

OpenAI is an artificial intelligence research organization that develops large-scale models and tools currently being scrutinized for potential cybersecurity risks.

California Department of Justice

The California Department of Justice acts as the state's primary law enforcement agency that investigates potential violations of cybersecurity and consumer protection statutes.

The details

The California Department of Justice utilizes subpoenas to compel responses regarding cybersecurity risks and industry compliance with state safety laws. This current action follows recent state legislative measures, including Senate Bill 1119 for chatbot children's safety and Senate Bill 867 governing chatbot-enabled toys.

Timeline

  1. January 2026: The California Department of Justice opened an investigation into nonconsensual sexually explicit material on X produced using Grok.

  2. September 2026: The Department of Justice announced its investigation into the Hugging Face incident.

  3. October 1, 2026: Attorney General Rob Bonta served the subpoena on OpenAI.

Roadmap

This investigation follows a trend of increasing state-level regulatory oversight aimed at the rapidly expanding AI sector. The enforcement efforts represent a departure from the industry's historical self-regulation toward a more structured, legal compliance framework.

While the subpoena process is an administrative move between the state and the company, it directly influences the safety standards users can expect from AI models. Future enforcement of laws like SB 1119 will likely result in more robust safeguards integrated into the chatbots and toys families use daily.

The takeaway

This subpoena signals that California is aggressively prioritizing security in the development of AI systems to prevent widespread cyber threats. Users should anticipate more frequent state-led interventions as officials aim to enforce stricter safety protocols across the technology sector.

Further reading

Learn more about local oversight at the Artificial Intelligence section.

More information

Review the full details regarding California Department of Justice incident reporting on the state portal.

Source note: This article includes information reported by The Santa Barbara Independent.

Live Poll

Should government authorities impose stricter cybersecurity and safety regulations on AI development companies?